Oracle Linux Security Advisory ELSA-2024-8127

http://linux.oracle.com/errata/ELSA-2024-8127.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
java-21-openjdk-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-demo-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-devel-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-headless-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-javadoc-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-javadoc-zip-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-jmods-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-src-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-static-libs-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-demo-fastdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-demo-slowdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-devel-fastdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-devel-slowdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-fastdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-headless-fastdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-headless-slowdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-jmods-fastdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-jmods-slowdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-slowdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-src-fastdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-src-slowdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-static-libs-fastdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm
java-21-openjdk-static-libs-slowdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm

aarch64:
java-21-openjdk-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-demo-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-devel-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-headless-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-javadoc-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-javadoc-zip-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-jmods-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-src-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-static-libs-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-demo-fastdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-demo-slowdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-devel-fastdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-devel-slowdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-fastdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-headless-fastdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-headless-slowdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-jmods-fastdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-jmods-slowdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-slowdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-src-fastdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-src-slowdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-static-libs-fastdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm
java-21-openjdk-static-libs-slowdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates//java-21-openjdk-21.0.5.0.10-3.0.1.el9.src.rpm

Related CVEs:

CVE-2023-48161
CVE-2024-21208
CVE-2024-21210
CVE-2024-21217
CVE-2024-21235




Description of changes:

[1:21.0.5.0.10-3.0.1]
- Add Oracle vendor bug URL [Orabug: 34340155]

[1:21.0.5.0.10-3]
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2024-10-15 @ 1pm PT. **
- Related: RHEL-61346

[1:21.0.5.0.10-2]
- Update to jdk-21.0.5+10 (GA)
- Update release notes to 21.0.5+10
- Bump giflib version to 5.2.2 following JDK-8328999
- Bump libpng version to 1.6.43 following JDK-8329004
- Vary portablesuffix depending on whether we are on RHEL ('el8') or CentOS ('el9')
- Handle debugedit being a separate package installed in /usr on RHEL/CentOS 10
- Add build scripts to repository to ease remembering all CentOS & RHEL targets and options
- Sync with RHEL 7 portable build:
- Use ExclusiveArch over ExcludeArch
- pkgos definition needs to be early enough to be used in portablesuffix
- Make build scripts executable
- Sync the copy of the portable specfile with the latest update
- Revert JDK-8327501 & JDK-8328366 backport until more mature.
- Resolves: RHEL-58798
- Resolves: RHEL-17186
- Resolves: RHEL-61346

_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle9: ELSA-2024-8127: java-21-openjdk Moderate Security Advisory Updates

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Summary

[1:21.0.5.0.10-3.0.1] - Add Oracle vendor bug URL [Orabug: 34340155] [1:21.0.5.0.10-3] - Sync the copy of the portable specfile with the latest update - ** This tarball is embargoed until 2024-10-15 @ 1pm PT. ** - Related: RHEL-61346 [1:21.0.5.0.10-2] - Update to jdk-21.0.5+10 (GA) - Update release notes to 21.0.5+10 - Bump giflib version to 5.2.2 following JDK-8328999 - Bump libpng version to 1.6.43 following JDK-8329004 - Vary portablesuffix depending on whether we are on RHEL ('el8') or CentOS ('el9') - Handle debugedit being a separate package installed in /usr on RHEL/CentOS 10 - Add build scripts to repository to ease remembering all CentOS & RHEL targets and options - Sync with RHEL 7 portable build: - Use ExclusiveArch over ExcludeArch - pkgos definition needs to be early enough to be used in portablesuffix - Make build scripts executable - Sync the copy of the portable specfile with the latest update - Revert JDK-8327501 & JDK-8328366 backport until more mature. - Resolv...

Read the Full Advisory

SRPMs

http://oss.oracle.com/ol9/SRPMS-updates//java-21-openjdk-21.0.5.0.10-3.0.1.el9.src.rpm

x86_64

java-21-openjdk-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-demo-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-devel-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-headless-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-javadoc-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-javadoc-zip-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-jmods-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-src-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-static-libs-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-demo-fastdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-demo-slowdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-devel-fastdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-devel-slowdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-fastdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-headless-fastdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-headless-slowdebug-21.0.5.0.10-3.0.1.el9.x86_64.rpm java-21-openjdk-jmods-fastdebug-21.0.5.0....

Read the Full Advisory

aarch64

java-21-openjdk-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-demo-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-devel-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-headless-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-javadoc-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-javadoc-zip-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-jmods-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-src-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-static-libs-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-demo-fastdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-demo-slowdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-devel-fastdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-devel-slowdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-fastdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-headless-fastdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-headless-slowdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-jmods-fastdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-jmods-slowdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-slowdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-src-fastdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-src-slowdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-static-libs-fastdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm java-21-openjdk-static-libs-slowdebug-21.0.5.0.10-3.0.1.el9.aarch64.rpm

i386

Severity
Related CVEs: CVE-2023-48161 CVE-2024-21208 CVE-2024-21210 CVE-2024-21217 CVE-2024-21235

Related News