Oracle Linux Security Advisory ELSA-2024-8117

http://linux.oracle.com/errata/ELSA-2024-8117.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
java-1.8.0-openjdk-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-accessibility-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-demo-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-devel-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-headless-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-javadoc-1.8.0.432.b06-2.0.1.el8.noarch.rpm
java-1.8.0-openjdk-javadoc-zip-1.8.0.432.b06-2.0.1.el8.noarch.rpm
java-1.8.0-openjdk-src-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-accessibility-fastdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-accessibility-slowdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-demo-fastdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-demo-slowdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-devel-fastdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-devel-slowdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-fastdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-headless-fastdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-headless-slowdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-slowdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-src-fastdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm
java-1.8.0-openjdk-src-slowdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm

aarch64:
java-1.8.0-openjdk-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-accessibility-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-demo-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-devel-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-headless-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-javadoc-1.8.0.432.b06-2.0.1.el8.noarch.rpm
java-1.8.0-openjdk-javadoc-zip-1.8.0.432.b06-2.0.1.el8.noarch.rpm
java-1.8.0-openjdk-src-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-accessibility-fastdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-accessibility-slowdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-demo-fastdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-demo-slowdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-devel-fastdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-devel-slowdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-fastdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-headless-fastdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-headless-slowdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-slowdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-src-fastdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm
java-1.8.0-openjdk-src-slowdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates//java-1.8.0-openjdk-1.8.0.432.b06-2.0.1.el8.src.rpm

Related CVEs:

CVE-2023-48161
CVE-2024-21208
CVE-2024-21210
CVE-2024-21217
CVE-2024-21235




Description of changes:

[1.8.0.432.b06-2.0.1]
- Add Oracle vendor bug URL [Orabug: 34340155]

[1:1.8.0.432.b06-1]
- Update to shenandoah-jdk8u432-b06 (GA)
- Update release notes for shenandoah-8u432-b06.
- Drop JDK-828109{6,7,8}/PR3836 patch following integration of upstream version
- Regenerate JDK-8199936/PR3533 patch following JDK-828109{6,7,8} integration
- Bump version of bundled zlib to 1.3.1 following JDK-8324632
- Include backport of JDK-8328999 to update giflib to 5.2.2
- Bump version of bundled giflib to 5.2.2 following JDK-8328999
- Add build scripts to repository to ease remembering all CentOS & RHEL targets and options
- Sync the copy of the portable specfile with the latest update
- Resolves: RHEL-58791
- Resolves: RHEL-62278
- Resolves: RHEL-61285
- ** This tarball is embargoed until 2024-10-15 @ 1pm PT. **


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle8: ELSA-2024-8117: java-1.8.0-openjdk Moderate Security Advisory Updates

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Summary

[1.8.0.432.b06-2.0.1] - Add Oracle vendor bug URL [Orabug: 34340155] [1:1.8.0.432.b06-1] - Update to shenandoah-jdk8u432-b06 (GA) - Update release notes for shenandoah-8u432-b06. - Drop JDK-828109{6,7,8}/PR3836 patch following integration of upstream version - Regenerate JDK-8199936/PR3533 patch following JDK-828109{6,7,8} integration - Bump version of bundled zlib to 1.3.1 following JDK-8324632 - Include backport of JDK-8328999 to update giflib to 5.2.2 - Bump version of bundled giflib to 5.2.2 following JDK-8328999 - Add build scripts to repository to ease remembering all CentOS & RHEL targets and options - Sync the copy of the portable specfile with the latest update - Resolves: RHEL-58791 - Resolves: RHEL-62278 - Resolves: RHEL-61285 - ** This tarball is embargoed until 2024-10-15 @ 1pm PT. **

SRPMs

http://oss.oracle.com/ol8/SRPMS-updates//java-1.8.0-openjdk-1.8.0.432.b06-2.0.1.el8.src.rpm

x86_64

java-1.8.0-openjdk-1.8.0.432.b06-2.0.1.el8.x86_64.rpm java-1.8.0-openjdk-accessibility-1.8.0.432.b06-2.0.1.el8.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.432.b06-2.0.1.el8.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.432.b06-2.0.1.el8.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.432.b06-2.0.1.el8.x86_64.rpm java-1.8.0-openjdk-javadoc-1.8.0.432.b06-2.0.1.el8.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.432.b06-2.0.1.el8.noarch.rpm java-1.8.0-openjdk-src-1.8.0.432.b06-2.0.1.el8.x86_64.rpm java-1.8.0-openjdk-accessibility-fastdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm java-1.8.0-openjdk-accessibility-slowdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm java-1.8.0-openjdk-demo-fastdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm java-1.8.0-openjdk-demo-slowdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm java-1.8.0-openjdk-devel-fastdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm java-1.8.0-openjdk-devel-slowdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm java-1.8.0-openjdk-fastdebug-1.8.0.432.b06-2.0.1.el8.x86_64.rpm java-1.8....

Read the Full Advisory

aarch64

java-1.8.0-openjdk-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-accessibility-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-demo-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-devel-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-headless-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-javadoc-1.8.0.432.b06-2.0.1.el8.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.432.b06-2.0.1.el8.noarch.rpm java-1.8.0-openjdk-src-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-accessibility-fastdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-accessibility-slowdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-demo-fastdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-demo-slowdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-devel-fastdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-devel-slowdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-fastdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-headless-fastdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-headless-slowdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-slowdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-src-fastdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm java-1.8.0-openjdk-src-slowdebug-1.8.0.432.b06-2.0.1.el8.aarch64.rpm

i386

Severity
Related CVEs: CVE-2023-48161 CVE-2024-21208 CVE-2024-21210 CVE-2024-21217 CVE-2024-21235

Related News