elsa-2022-5695
oracle_linux[1:11.0.16.0.8-1.0.1] - Replace upstream references [Orabug: 34340155] [1:11.0.16.0.8-1] - Update to jdk-11.0.16+8 - Update release notes to 11.0.16+8 - Use same tarball naming style as java-17-openjdk and java-latest-openjdk - Drop JDK-8257794 patch now upstreamed - Print release file during build, which should now include a correct SOURCE value from .src-rev - Update tarball script with IcedTea GitHub URL and .src-rev generation - Use 'git apply' with patches in the tarball script to allow binary diffs - Include script to generate bug list for release notes - Update tzdata requirement to 2022a to match JDK-8283350 - Make use of the vendor version string to store our version release rather than an upstream release date - Explicitly require crypto-policies during build and runtime for system security properties - Rebase FIPS patches from fips branch and simplify by using a single patch from that repository - * RH2036462: sun.security.pkcs11.wrapper.PKCS11.getInstance breakage - * RH2090378: Revert to disabling system security properties and FIPS mode support together - Rebase RH1648249 nss.cfg patch so it applies after the FIPS patch - Enable system security properties in the RPM (now disabled by default in the FIPS repo) - Improve security properties test to check both enabled and disabled behaviour - Run security properties test with property debugging on - Resolves: rhbz#2106516 - Resolves: rhbz#2099915 - Resolves: rhbz#2107868 [1:11.0.16.0.8-1] - Add additional patch during tarball generation to align tests with ECC changes - Related: rhbz#2106516 [1:11.0.16.0.8-1] - RH2007331: SecretKey generate/import operations don't add the CKA_SIGN attribute in FIPS mode - Resolves: rhbz#2107866
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"cves": [
"CVE-2022-34169",
"CVE-2022-21541",
"CVE-2022-21540"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[1:11.0.16.0.8-1.0.1]\n- Replace upstream references [Orabug: 34340155]\n\n[1:11.0.16.0.8-1]\n- Update to jdk-11.0.16+8\n- Update release notes to 11.0.16+8\n- Use same tarball naming style as java-17-openjdk and java-latest-openjdk\n- Drop JDK-8257794 patch now upstreamed\n- Print release file during build, which should now include a correct SOURCE value from .src-rev\n- Update tarball script with IcedTea GitHub URL and .src-rev generation\n- Use 'git apply' with patches in the tarball script to allow binary diffs\n- Include script to generate bug list for release notes\n- Update tzdata requirement to 2022a to match JDK-8283350\n- Make use of the vendor version string to store our version release rather than an upstream release date\n- Explicitly require crypto-policies during build and runtime for system security properties\n- Rebase FIPS patches from fips branch and simplify by using a single patch from that repository\n- * RH2036462: sun.security.pkcs11.wrapper.PKCS11.getInstance breakage\n- * RH2090378: Revert to disabling system security properties and FIPS mode support together\n- Rebase RH1648249 nss.cfg patch so it applies after the FIPS patch\n- Enable system security properties in the RPM (now disabled by default in the FIPS repo)\n- Improve security properties test to check both enabled and disabled behaviour\n- Run security properties test with property debugging on\n- Resolves: rhbz#2106516\n- Resolves: rhbz#2099915\n- Resolves: rhbz#2107868\n\n[1:11.0.16.0.8-1]\n- Add additional patch during tarball generation to align tests with ECC changes\n- Related: rhbz#2106516\n\n[1:11.0.16.0.8-1]\n- RH2007331: SecretKey generate/import operations don't add the CKA_SIGN attribute in FIPS mode\n- Resolves: rhbz#2107866",
"id": "ELSA-2022-5695",
"ovalId": "oval:com.oracle.elsa:def:20225695",
"source": "oracle_linux",
"title": "ELSA-2022-5695: java-11-openjdk security, bug fix, and enhancement update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2022-5695.html"
}