{"cves":["CVE-2026-41254","CVE-2026-46968","CVE-2026-47010","CVE-2026-47021","CVE-2026-47027","CVE-2026-47057","CVE-2026-47058","CVE-2026-47059","CVE-2026-47063","CVE-2026-60147"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[1:1.8.0.502.b07-1.1.0.1]\n- Add Oracle vendor bug URL [Orabug: 34340155]\n\n[1:1.8.0.502.b07-1.1]\n- Update to 8u502-b07 (GA).\n- Update release notes for 8u502-b07.\n- Bump lcms2 version to 2.19.1 following JDK-8321489, JDK-8348110, JDK-8375065  JDK-8383354\n- Bump zlib version to 1.3.2 following JDK-8378631\n- Require tzdata 2026b due to upstream inclusion of JDK-8383175\n- Add attempted patch for JDK-8385876 to fix -Wnonnull build failure with s390x Zero on CentOS 9\n- Remove macro references in comments where possible (%dnl not compatible enough yet)\n- Move version information and core NVR definitions back towards the top of the file\n- Explictly define supported architectures\n- Specify portablerelease and rpmrelease (always 0 for portables) in the Release field\n- Make zone string debug output optional in TestTranslations\n- Change javadoc-zip to just own the top-level directory, not include the entire subtree\n- Update tagged versions to include 9.8.0-z  9.9.0.\n- Cleanup tagging and gating scripts to appease shellcheck:\n- * scripts/builds/build_vanilla.sh: Use an array to handle the varying arguments to rhpkg.\n- * scripts/builds/check_signatures.sh: Quote variable usage.\n- * scripts/builds/waive_issue.sh: Remove redundant 'test 'x'' usage.\n- * scripts/builds/waive_leapp_issue.sh: Likewise.\n- * scripts/builds/waive_rpminspect.sh: Likewise.\n- * scripts/builds/waive_usual_rpminspect.sh: Likewise and add missing WORKING_DIR variable.\n- * scripts/builds/waive_usual_tier0.sh: Remove redundant 'test 'x'' usage.\n- Obsolete old RHEL releases (8.2.0-z, 9.0.0-z, 9.7.0-z)\n- Sync the copy of the portable specfile with the latest update\n- Sync portable naming with later JDKs, due to adoption of compatiblename by portable\n- Drop pversion which is a redundant alias for version now\n- Update tagging scripts to include signature checks and correctly handle gating\n- Add gating scripts to simplify obtaining results and waiving issues\n- ** This tarball is embargoed until 2026-07-21 @ 1pm PT. **\n- Resolves: RHEL-212354\n- Resolves: RHEL-188874\n- Resolves: RHEL-212132\n- Resolves: RHEL-212311\n- Resolves: RHEL-212317\n- Related: RHEL-212322\n- Resolves: RHEL-212355\n- Resolves: RHEL-212356\n- Resolves: RHEL-212357\n- Resolves: RHEL-212358\n\n[1:1.8.0.502.b07-1.1]\n- Make headless own /usr/share/doc/java-1.8.0-openjdk\n- Make javadoc-zip own /usr/share/javadoc/java-1.8.0-openjdk\n- Resolves: RHEL-212322","id":"ELSA-2026-42877","ovalId":"oval:com.oracle.elsa:def:202642877","source":"oracle_linux","title":"ELSA-2026-42877:  java-1.8.0-openjdk security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-42877.html"}