ELSA-2024-1817

ELSA-2024-1817 - java-1.8.0-openjdk security update

Type:SECURITY
Impact:MODERATE
Release Date:2024-04-17

Description


[1:1.8.0.412.b08-1]
- Update to shenandoah-jdk8u412-b08 (GA)
- Update release notes for shenandoah-8u412-b08.
- Complete release note for Certainly roots
- Switch to GA mode.
- ** This tarball is embargoed until 2024-04-16 @ 1pm PT. **
- Related: RHEL-30926

[1:1.8.0.412.b07-0.1.ea]
- Update to shenandoah-jdk8u412-b07 (EA)
- Update release notes for shenandoah-8u412-b07.
- Require tzdata 2024a due to upstream inclusion of JDK-8322725
- Only require tzdata 2023d for now as 2024a is unavailable in buildroot
- Resolves: RHEL-30926

[1:1.8.0.412.b01-0.1.ea]
- Turn off xz multi-threading on i686 as it fails with an out of memory error
- Normalise whitespace
- Move to upstream tag style (shenandoah8ux-by) in preparation for eventually moving back to official sources
- generate_source_tarball.sh: Rename JCONSOLE_JS_PATCH{,_DEFAULT} to JCONSOLE_PATCH{,_DEFAULT} for brevity
- generate_source_tarball.sh: Adapt OPENJDK_LATEST logic to work with 8u Shenandoah fork
- generate_source_tarball.sh: Adapt version logic to work with 8u
- generate_source_tarball.sh: Add quoting for SCRIPT_DIR and JCONSOLE_PATCH (SC2086)
- generate_source_tarball.sh: Update examples in header for clarity
- generate_source_tarball.sh: Create directory in TMPDIR when using WITH_TEMP
- generate_source_tarball.sh: Only add --depth=1 on non-local repositories
- Move maintenance scripts to a scripts subdirectory
- icedtea_sync.sh: Update with a VCS mode that retrieves sources from a Mercurial repository
- jconsole.desktop.in: Restored by running icedtea_sync.sh
- policytool.desktop.in: Likewise.
- Restore IcedTea sources correctly in spec file
- discover_trees.sh: Set compile-command and indentation instructions for Emacs
- discover_trees.sh: shellcheck: Do not use -o (SC2166)
- discover_trees.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- discover_trees.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: Add authorship
- icedtea_sync.sh: Set compile-command and indentation instructions for Emacs
- icedtea_sync.sh: shellcheck: Double-quote variable references (SC2086)
- icedtea_sync.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: Set compile-command and indentation instructions for Emacs
- openjdk_news.sh: shellcheck: Double-quote variable references (SC2086)
- openjdk_news.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- openjdk_news.sh: shellcheck: Remove deprecated egrep usage (SC2196)
- generate_source_tarball.sh: Handle an existing checkout
- generate_source_tarball.sh: Sync indentation with java-21-openjdk version
- generate_source_tarball.sh: Support using a subdirectory via TO_COMPRESS
- Related: RHEL-30926

[1:1.8.0.412.b01-0.1.ea]
- Invoke xz in multi-threaded mode
- generate_source_tarball.sh: Add WITH_TEMP environment variable
- generate_source_tarball.sh: Multithread xz on all available cores
- generate_source_tarball.sh: Add OPENJDK_LATEST environment variable
- generate_source_tarball.sh: Update comment about tarball naming
- generate_source_tarball.sh: Reformat comment header
- generate_source_tarball.sh: Reformat and update help output
- generate_source_tarball.sh: Do a shallow clone, for speed
- generate_source_tarball.sh: Eliminate some removal prompting
- generate_source_tarball.sh: Make tarball reproducible
- generate_source_tarball.sh: Prefix temporary directory with temp-
- generate_source_tarball.sh: Remove temporary directory exit conditions
- generate_source_tarball.sh: Set compile-command in Emacs
- generate_source_tarball.sh: Remove REPO_NAME from FILE_NAME_ROOT
- generate_source_tarball.sh: Move PROJECT_NAME and REPO_NAME checks
- generate_source_tarball.sh: shellcheck: Remove x-prefixes since we use Bash (SC2268)
- generate_source_tarball.sh: shellcheck: Double-quote variable references (SC2086)
- generate_source_tarball.sh: shellcheck: Do not use -a (SC2166)
- generate_source_tarball.sh: shellcheck: Do not use $ on arithmetic variables (SC2004)
- Use backward-compatible patch syntax
- generate_source_tarball.sh: Ignore -ga tags with OPENJDK_LATEST
- generate_source_tarball.sh: Remove trailing period in echo
- generate_source_tarball.sh: Use long-style argument to grep
- generate_source_tarball.sh: Add license
- generate_source_tarball.sh: Add indentation instructions for Emacs
- Remove -T0 argument from systemtap tar invocation
- Related: RHEL-30926

[1:1.8.0.412.b01-0.1.ea]
- Update to shenandoah-jdk8u412-b01 (EA)
- Update release notes for shenandoah-8u412-b01.
- Switch to EA mode.
- Related: RHEL-30926


Related CVEs


CVE-2024-21085
CVE-2024-21068
CVE-2024-21094
CVE-2024-21011

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 7 (aarch64) java-1.8.0-openjdk-1.8.0.412.b08-1.el7_9.src.rpmd9d803080eda24347155e8aeb332202fe4c74a3c0e0729a630d406c8b99ba4c1ELBA-2025-0417ol7_aarch64_latest
java-1.8.0-openjdk-1.8.0.412.b08-1.el7_9.src.rpmd9d803080eda24347155e8aeb332202fe4c74a3c0e0729a630d406c8b99ba4c1ELBA-2025-0417ol7_aarch64_optional_latest
java-1.8.0-openjdk-1.8.0.412.b08-1.el7_9.src.rpmd9d803080eda24347155e8aeb332202fe4c74a3c0e0729a630d406c8b99ba4c1ELBA-2025-0417ol7_aarch64_u9_patch
java-1.8.0-openjdk-1.8.0.412.b08-1.el7_9.aarch64.rpm43728c7b5146e1312d406598c7def9bc6f2c449a90ecc2cbfe9e648356485717ELBA-2025-0417ol7_aarch64_latest
java-1.8.0-openjdk-1.8.0.412.b08-1.el7_9.aarch64.rpm43728c7b5146e1312d406598c7def9bc6f2c449a90ecc2cbfe9e648356485717ELBA-2025-0417ol7_aarch64_u9_patch
java-1.8.0-openjdk-accessibility-1.8.0.412.b08-1.el7_9.aarch64.rpm650c2527132d5ed0735d4c3c937852f0e9cf36305af80051ff87b48bd7d6db9eELBA-2025-0417ol7_aarch64_optional_latest
java-1.8.0-openjdk-demo-1.8.0.412.b08-1.el7_9.aarch64.rpm1836481e095ed659588507f36d365cc49d68cd51b9d06a57f4f901f685db6e2bELBA-2025-0417ol7_aarch64_optional_latest
java-1.8.0-openjdk-devel-1.8.0.412.b08-1.el7_9.aarch64.rpm54d63eeb563d2c232429f1acf368a3b1fdf14f32bc18851cd639a84eaf9240b6ELBA-2025-0417ol7_aarch64_latest
java-1.8.0-openjdk-devel-1.8.0.412.b08-1.el7_9.aarch64.rpm54d63eeb563d2c232429f1acf368a3b1fdf14f32bc18851cd639a84eaf9240b6ELBA-2025-0417ol7_aarch64_u9_patch
java-1.8.0-openjdk-headless-1.8.0.412.b08-1.el7_9.aarch64.rpme4eb1d79824a59d3d973fb2d6ae1d49e14266de24493979a742cc6350216e38bELBA-2025-0417ol7_aarch64_latest
java-1.8.0-openjdk-headless-1.8.0.412.b08-1.el7_9.aarch64.rpme4eb1d79824a59d3d973fb2d6ae1d49e14266de24493979a742cc6350216e38bELBA-2025-0417ol7_aarch64_u9_patch
java-1.8.0-openjdk-javadoc-1.8.0.412.b08-1.el7_9.noarch.rpm153c352864d508ff9f0b53c506e1a34d016cdd963bb80545ec590a8c11e5fab8ELBA-2025-0417ol7_aarch64_optional_latest
java-1.8.0-openjdk-javadoc-zip-1.8.0.412.b08-1.el7_9.noarch.rpm924e0e018a5c38c5a8829975df6017de33e1bb38704529dce401f98008c1740aELBA-2025-0417ol7_aarch64_optional_latest
java-1.8.0-openjdk-src-1.8.0.412.b08-1.el7_9.aarch64.rpm2cac06f240e940ffb5c02ec002f66273955e0758506527001a70588443e97ddcELBA-2025-0417ol7_aarch64_optional_latest
Oracle Linux 7 (x86_64) java-1.8.0-openjdk-1.8.0.412.b08-1.el7_9.src.rpmd9d803080eda24347155e8aeb332202fe4c74a3c0e0729a630d406c8b99ba4c1ELBA-2025-0417ol7_x86_64_latest
java-1.8.0-openjdk-1.8.0.412.b08-1.el7_9.src.rpmd9d803080eda24347155e8aeb332202fe4c74a3c0e0729a630d406c8b99ba4c1ELBA-2025-0417ol7_x86_64_optional_latest
java-1.8.0-openjdk-1.8.0.412.b08-1.el7_9.src.rpmd9d803080eda24347155e8aeb332202fe4c74a3c0e0729a630d406c8b99ba4c1ELBA-2025-0417ol7_x86_64_u9_patch
java-1.8.0-openjdk-1.8.0.412.b08-1.el7_9.i686.rpm5b1b9fb5d09e0670ccf2c12dec1873447a2aad9cdcec5f00ca5833a3539101fdELBA-2025-0417ol7_x86_64_latest
java-1.8.0-openjdk-1.8.0.412.b08-1.el7_9.i686.rpm5b1b9fb5d09e0670ccf2c12dec1873447a2aad9cdcec5f00ca5833a3539101fdELBA-2025-0417ol7_x86_64_u9_patch
java-1.8.0-openjdk-1.8.0.412.b08-1.el7_9.x86_64.rpme8e6189cd43776e6c3ce83088676ac89a7b8f1ad2f5ff4e16d9074bc7968c22aELBA-2025-0417ol7_x86_64_latest
java-1.8.0-openjdk-1.8.0.412.b08-1.el7_9.x86_64.rpme8e6189cd43776e6c3ce83088676ac89a7b8f1ad2f5ff4e16d9074bc7968c22aELBA-2025-0417ol7_x86_64_u9_patch
java-1.8.0-openjdk-accessibility-1.8.0.412.b08-1.el7_9.i686.rpm4dce696ecb55c15888a70e7f01139887f043d53231393dffa80fc98e2ee4d434ELBA-2025-0417ol7_x86_64_optional_latest
java-1.8.0-openjdk-accessibility-1.8.0.412.b08-1.el7_9.x86_64.rpm32a349afe96e3388060b38929fe1b8982ab6220e36d61305b80c842fac7fadfeELBA-2025-0417ol7_x86_64_optional_latest
java-1.8.0-openjdk-demo-1.8.0.412.b08-1.el7_9.i686.rpm091fb317d4d42e5a1e4946edc3641329a8b7fe54535a973f5acfd4383ec49186ELBA-2025-0417ol7_x86_64_optional_latest
java-1.8.0-openjdk-demo-1.8.0.412.b08-1.el7_9.x86_64.rpm0eedda1811c2f8e4a117584d37f74c6b2c64e036c8259340d0fc2dbb21e502eeELBA-2025-0417ol7_x86_64_optional_latest
java-1.8.0-openjdk-devel-1.8.0.412.b08-1.el7_9.i686.rpm52bc40d11631bdb97c95856f3c86adbf541193c67119112c180ccd2f5c67199eELBA-2025-0417ol7_x86_64_latest
java-1.8.0-openjdk-devel-1.8.0.412.b08-1.el7_9.i686.rpm52bc40d11631bdb97c95856f3c86adbf541193c67119112c180ccd2f5c67199eELBA-2025-0417ol7_x86_64_u9_patch
java-1.8.0-openjdk-devel-1.8.0.412.b08-1.el7_9.x86_64.rpmea02a11a3f132c2f2a26373874dcba11fbf9f711959c152b7e43aeebfbad1843ELBA-2025-0417ol7_x86_64_latest
java-1.8.0-openjdk-devel-1.8.0.412.b08-1.el7_9.x86_64.rpmea02a11a3f132c2f2a26373874dcba11fbf9f711959c152b7e43aeebfbad1843ELBA-2025-0417ol7_x86_64_u9_patch
java-1.8.0-openjdk-headless-1.8.0.412.b08-1.el7_9.i686.rpm6598ec262634faca81acf971355a83654eadaf517fc68c81f89cff0552e1fd78ELBA-2025-0417ol7_x86_64_latest
java-1.8.0-openjdk-headless-1.8.0.412.b08-1.el7_9.i686.rpm6598ec262634faca81acf971355a83654eadaf517fc68c81f89cff0552e1fd78ELBA-2025-0417ol7_x86_64_u9_patch
java-1.8.0-openjdk-headless-1.8.0.412.b08-1.el7_9.x86_64.rpm94d1f2dc18e09c27c65992888049e158f566651c66563c5faaf0bd4038bec62bELBA-2025-0417ol7_x86_64_latest
java-1.8.0-openjdk-headless-1.8.0.412.b08-1.el7_9.x86_64.rpm94d1f2dc18e09c27c65992888049e158f566651c66563c5faaf0bd4038bec62bELBA-2025-0417ol7_x86_64_u9_patch
java-1.8.0-openjdk-javadoc-1.8.0.412.b08-1.el7_9.noarch.rpm153c352864d508ff9f0b53c506e1a34d016cdd963bb80545ec590a8c11e5fab8ELBA-2025-0417ol7_x86_64_optional_latest
java-1.8.0-openjdk-javadoc-zip-1.8.0.412.b08-1.el7_9.noarch.rpm924e0e018a5c38c5a8829975df6017de33e1bb38704529dce401f98008c1740aELBA-2025-0417ol7_x86_64_optional_latest
java-1.8.0-openjdk-src-1.8.0.412.b08-1.el7_9.i686.rpmca24394f48aa7b9b0983e5dbea95173c3f127d2e0d95d441408ef920222c01a6ELBA-2025-0417ol7_x86_64_latest
java-1.8.0-openjdk-src-1.8.0.412.b08-1.el7_9.i686.rpmca24394f48aa7b9b0983e5dbea95173c3f127d2e0d95d441408ef920222c01a6ELBA-2025-0417ol7_x86_64_u9_patch
java-1.8.0-openjdk-src-1.8.0.412.b08-1.el7_9.x86_64.rpmdd67c58593e7bd0f6b50a4b8162b7eeac3415cb12fc44e8e5ea76c5acd378480ELBA-2025-0417ol7_x86_64_optional_latest



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete