Oracle Linux Security Advisory ELSA-2024-8116

http://linux.oracle.com/errata/ELSA-2024-8116.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
java-1.8.0-openjdk-1.8.0.432.b06-1.0.1.el7_9.i686.rpm
java-1.8.0-openjdk-1.8.0.432.b06-1.0.1.el7_9.x86_64.rpm
java-1.8.0-openjdk-accessibility-1.8.0.432.b06-1.0.1.el7_9.i686.rpm
java-1.8.0-openjdk-accessibility-1.8.0.432.b06-1.0.1.el7_9.x86_64.rpm
java-1.8.0-openjdk-demo-1.8.0.432.b06-1.0.1.el7_9.i686.rpm
java-1.8.0-openjdk-demo-1.8.0.432.b06-1.0.1.el7_9.x86_64.rpm
java-1.8.0-openjdk-devel-1.8.0.432.b06-1.0.1.el7_9.i686.rpm
java-1.8.0-openjdk-devel-1.8.0.432.b06-1.0.1.el7_9.x86_64.rpm
java-1.8.0-openjdk-headless-1.8.0.432.b06-1.0.1.el7_9.i686.rpm
java-1.8.0-openjdk-headless-1.8.0.432.b06-1.0.1.el7_9.x86_64.rpm
java-1.8.0-openjdk-javadoc-1.8.0.432.b06-1.0.1.el7_9.noarch.rpm
java-1.8.0-openjdk-javadoc-zip-1.8.0.432.b06-1.0.1.el7_9.noarch.rpm
java-1.8.0-openjdk-src-1.8.0.432.b06-1.0.1.el7_9.i686.rpm
java-1.8.0-openjdk-src-1.8.0.432.b06-1.0.1.el7_9.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates//java-1.8.0-openjdk-1.8.0.432.b06-1.0.1.el7_9.src.rpm

Related CVEs:

CVE-2023-48161
CVE-2024-21208
CVE-2024-21210
CVE-2024-21217
CVE-2024-21235




Description of changes:

[1:1.8.0.432.b06-1.0.1]
- Update to shenandoah8u432-b06 [Orabug: 37185223]
- Fixes CVE-2024-21208 CVE-2024-21210 CVE-2024-21217 CVE-2024-21235
- Removed patches
- 1001-orabug36904359-CVE-2024-21131-fix.patch
- 1002-orabug36904359-CVE-2024-21138-fix.patch
- 1003-orabug36904359-CVE-2024-21140-fix-part1.patch
- 1004-orabug36904359-CVE-2024-21140-fix-part2.patch
- 1005-orabug36904359-CVE-2024-21140-fix-part3.patch
- 1006-orabug36904359-CVE-2024-21144-fix.patch
- 1007-orabug36904359-CVE-2024-21145-fix.patch
- 1008-orabug36904359-CVE-2024-21147-fix.patch
- rh1648644-java_access_bridge_privileged_security.patch
- jdk8186464-rh1433262-zip64_failure.patch
- rh1684077-openjdk_should_depend_on_pcsc-lite-libs_instead_of_pcsc-lite-devel.patch
- jdk8199936-pr3533-enable_mstackrealign_on_x86_linux_as_well_as_x86_mac_os_x.patch
- pr2462-resolve_disabled_warnings_for_libunpack_and_the_unpack200_binary.patch
- Added following patches:
- jdk8186464-rh1433262-zip64_failure_ol7.patch
- rh1684077-openjdk_should_depend_on_pcsc-lite-libs_instead_of_pcsc-lite-devel_ol7.patch
- jdk8199936-pr3533-enable_mstackrealign_on_x86_linux_as_well_as_x86_mac_os_x_ol7.patch
- pr2462-resolve_disabled_warnings_for_libunpack_and_the_unpack200_binary_ol7.patch


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle7: ELSA-2024-8116: java-1.8.0-openjdk Moderate Security Advisory Updates

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Summary

[1:1.8.0.432.b06-1.0.1] - Update to shenandoah8u432-b06 [Orabug: 37185223] - Fixes CVE-2024-21208 CVE-2024-21210 CVE-2024-21217 CVE-2024-21235 - Removed patches - 1001-orabug36904359-CVE-2024-21131-fix.patch - 1002-orabug36904359-CVE-2024-21138-fix.patch - 1003-orabug36904359-CVE-2024-21140-fix-part1.patch - 1004-orabug36904359-CVE-2024-21140-fix-part2.patch - 1005-orabug36904359-CVE-2024-21140-fix-part3.patch - 1006-orabug36904359-CVE-2024-21144-fix.patch - 1007-orabug36904359-CVE-2024-21145-fix.patch - 1008-orabug36904359-CVE-2024-21147-fix.patch - rh1648644-java_access_bridge_privileged_security.patch - jdk8186464-rh1433262-zip64_failure.patch - rh1684077-openjdk_should_depend_on_pcsc-lite-libs_instead_of_pcsc-lite-devel.patch - jdk8199936-pr3533-enable_mstackrealign_on_x86_linux_as_well_as_x86_mac_os_x.patch - pr2462-resolve_disabled_warnings_for_libunpack_and_the_unpack200_binary.patch - Added following patches: - jdk8186464-rh1433262-zip64_failure_ol7.patch - rh1684077-openjd...

Read the Full Advisory

SRPMs

http://oss.oracle.com/ol7/SRPMS-updates//java-1.8.0-openjdk-1.8.0.432.b06-1.0.1.el7_9.src.rpm

x86_64

java-1.8.0-openjdk-1.8.0.432.b06-1.0.1.el7_9.i686.rpm java-1.8.0-openjdk-1.8.0.432.b06-1.0.1.el7_9.x86_64.rpm java-1.8.0-openjdk-accessibility-1.8.0.432.b06-1.0.1.el7_9.i686.rpm java-1.8.0-openjdk-accessibility-1.8.0.432.b06-1.0.1.el7_9.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.432.b06-1.0.1.el7_9.i686.rpm java-1.8.0-openjdk-demo-1.8.0.432.b06-1.0.1.el7_9.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.432.b06-1.0.1.el7_9.i686.rpm java-1.8.0-openjdk-devel-1.8.0.432.b06-1.0.1.el7_9.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.432.b06-1.0.1.el7_9.i686.rpm java-1.8.0-openjdk-headless-1.8.0.432.b06-1.0.1.el7_9.x86_64.rpm java-1.8.0-openjdk-javadoc-1.8.0.432.b06-1.0.1.el7_9.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.432.b06-1.0.1.el7_9.noarch.rpm java-1.8.0-openjdk-src-1.8.0.432.b06-1.0.1.el7_9.i686.rpm java-1.8.0-openjdk-src-1.8.0.432.b06-1.0.1.el7_9.x86_64.rpm

aarch64

i386

Severity
Related CVEs: CVE-2023-48161 CVE-2024-21208 CVE-2024-21210 CVE-2024-21217 CVE-2024-21235

Related News