Oracle Linux Security Advisory ELSA-2025-0426

http://linux.oracle.com/errata/ELSA-2025-0426.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
java-21-openjdk-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-demo-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-devel-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-headless-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-javadoc-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-javadoc-zip-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-jmods-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-src-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-static-libs-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-demo-fastdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-demo-slowdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-devel-fastdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-devel-slowdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-fastdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-headless-fastdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-headless-slowdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-jmods-fastdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-jmods-slowdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-slowdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-src-fastdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-src-slowdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-static-libs-fastdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm
java-21-openjdk-static-libs-slowdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm

aarch64:
java-21-openjdk-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-demo-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-devel-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-headless-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-javadoc-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-javadoc-zip-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-jmods-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-src-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-static-libs-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-demo-fastdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-demo-slowdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-devel-fastdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-devel-slowdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-fastdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-headless-fastdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-headless-slowdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-jmods-fastdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-jmods-slowdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-slowdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-src-fastdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-src-slowdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-static-libs-fastdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm
java-21-openjdk-static-libs-slowdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates//java-21-openjdk-21.0.6.0.7-1.0.1.el8.src.rpm

Related CVEs:

CVE-2025-21502




Description of changes:

[1:21.0.6.0.7-1.0.1]
- Add Oracle vendor bug URL [Orabug: 34340155]

[1:21.0.6.0.7-1]
- Update to jdk-21.0.6+7 (GA)
- Update release notes to 21.0.6+7
- Sync the copy of the portable & devkit specfiles with the latest update
- Include the latest devkit patches
- Update README.md to list an easier way of disabling the devkit
- ** This tarball is embargoed until 2025-01-21 @ 1pm PT. **
- Resolves: RHEL-73549

[1:21.0.5.0.11-3]
- Transition to the devkit build by not defining pkgos
- Exempt x86_64 from the static libs debuginfo test until portable uses an older DWARF version
- Sync the copy of the portable specfile with the devkit version
- Include the devkit specfile and patches
- Document the devkit in README.md
- Resolves: RHEL-74404

[1:21.0.5.0.11-2]
- Update to jdk-21.0.5+11 (GA)
- Update release notes to 21.0.5+11
- Remove local JDK-8327501 & JDK-8328366 backport as this is now upstream.
- Sync the copy of the portable specfile with the latest update
- Related: RHEL-61346


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle8: ELSA-2025-0426: java-21-openjdk for RHEL 8.10, 9.4 and 9.5 Moderate Security Advisory Updates

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Summary

[1:21.0.6.0.7-1.0.1] - Add Oracle vendor bug URL [Orabug: 34340155] [1:21.0.6.0.7-1] - Update to jdk-21.0.6+7 (GA) - Update release notes to 21.0.6+7 - Sync the copy of the portable & devkit specfiles with the latest update - Include the latest devkit patches - Update README.md to list an easier way of disabling the devkit - ** This tarball is embargoed until 2025-01-21 @ 1pm PT. ** - Resolves: RHEL-73549 [1:21.0.5.0.11-3] - Transition to the devkit build by not defining pkgos - Exempt x86_64 from the static libs debuginfo test until portable uses an older DWARF version - Sync the copy of the portable specfile with the devkit version - Include the devkit specfile and patches - Document the devkit in README.md - Resolves: RHEL-74404 [1:21.0.5.0.11-2] - Update to jdk-21.0.5+11 (GA) - Update release notes to 21.0.5+11 - Remove local JDK-8327501 & JDK-8328366 backport as this is now upstream. - Sync the copy of the portable specfile with the latest update - Related: RHEL-61346

SRPMs

http://oss.oracle.com/ol8/SRPMS-updates//java-21-openjdk-21.0.6.0.7-1.0.1.el8.src.rpm

x86_64

java-21-openjdk-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-demo-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-devel-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-headless-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-javadoc-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-javadoc-zip-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-jmods-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-src-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-static-libs-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-demo-fastdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-demo-slowdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-devel-fastdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-devel-slowdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-fastdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-headless-fastdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-headless-slowdebug-21.0.6.0.7-1.0.1.el8.x86_64.rpm java-21-openjdk-jmods-fastdebug-21.0.6.0.7-1.0.1.el8.x86_...

Read the Full Advisory

aarch64

java-21-openjdk-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-demo-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-devel-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-headless-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-javadoc-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-javadoc-zip-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-jmods-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-src-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-static-libs-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-demo-fastdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-demo-slowdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-devel-fastdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-devel-slowdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-fastdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-headless-fastdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-headless-slowdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-jmods-fastdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-jmods-slowdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-slowdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-src-fastdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-src-slowdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-static-libs-fastdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm java-21-openjdk-static-libs-slowdebug-21.0.6.0.7-1.0.1.el8.aarch64.rpm

i386

Severity
Related CVEs: CVE-2025-21502

Related News