Lucene search

K
oraclelinuxOracleLinuxELSA-2024-4573
HistoryJul 18, 2024 - 12:00 a.m.

java-21-openjdk security update

2024-07-1800:00:00
linux.oracle.com
7
java
openjdk update
security fixes
release notes
resolves rhel-47009
rhel-45358
rhel-47398
rhel-46027
embargoed
ea mode
ga mode
tzdata 2024a

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

[1:21.0.4.0.7-1.0.1]

  • Add Oracle vendor bug URL [Orabug: 34340155]
    [1:21.0.4.0.7-1]
  • Update to jdk-21.0.4+7 (GA)
  • Update release notes to 21.0.4+7
  • Switch to GA mode.
  • Sync the copy of the portable specfile with the latest update
  • Add missing section headers in NEWS
  • This tarball is embargoed until 2024-07-16 @ 1pm PT.
  • Resolves: RHEL-47022
    [1:21.0.4.0.5-0.1.ea]
  • Update to jdk-21.0.4+5 (EA)
  • Update release notes to 21.0.4+5
  • Limit Java only tests to one architecture using jdk_test_arch
  • Actually require tzdata 2024a now it is available in the buildroot
  • Resolves: RHEL-45356
  • Resolves: RHEL-47399
    [1:21.0.4.0.1-0.1.ea]
  • Update to jdk-21.0.4+1 (EA)
  • Update release notes to 21.0.4+1
  • Switch to EA mode
  • Bump LCMS 2 version to 2.16.0 following JDK-8321489
  • Add zlib build requirement or bundled version (1.3.1), depending on system_libs setting
  • Restore NEWS file so portable can be rebuilt
  • Sync the copy of the portable specfile with the latest update
  • Related: RHEL-45356
  • Resolves: RHEL-46028

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N