elsa-2026-42877
oracle_linux[1:1.8.0.502.b07-1.1.0.1] - Add Oracle vendor bug URL [Orabug: 34340155] [1:1.8.0.502.b07-1.1] - Update to 8u502-b07 (GA). - Update release notes for 8u502-b07. - Bump lcms2 version to 2.19.1 following JDK-8321489, JDK-8348110, JDK-8375065 JDK-8383354 - Bump zlib version to 1.3.2 following JDK-8378631 - Require tzdata 2026b due to upstream inclusion of JDK-8383175 - Add attempted patch for JDK-8385876 to fix -Wnonnull build failure with s390x Zero on CentOS 9 - Remove macro references in comments where possible (%dnl not compatible enough yet) - Move version information and core NVR definitions back towards the top of the file - Explictly define supported architectures - Specify portablerelease and rpmrelease (always 0 for portables) in the Release field - Make zone string debug output optional in TestTranslations - Change javadoc-zip to just own the top-level directory, not include the entire subtree - Update tagged versions to include 9.8.0-z 9.9.0. - Cleanup tagging and gating scripts to appease shellcheck: - * scripts/builds/build_vanilla.sh: Use an array to handle the varying arguments to rhpkg. - * scripts/builds/check_signatures.sh: Quote variable usage. - * scripts/builds/waive_issue.sh: Remove redundant 'test 'x'' usage. - * scripts/builds/waive_leapp_issue.sh: Likewise. - * scripts/builds/waive_rpminspect.sh: Likewise. - * scripts/builds/waive_usual_rpminspect.sh: Likewise and add missing WORKING_DIR variable. - * scripts/builds/waive_usual_tier0.sh: Remove redundant 'test 'x'' usage. - Obsolete old RHEL releases (8.2.0-z, 9.0.0-z, 9.7.0-z) - Sync the copy of the portable specfile with the latest update - Sync portable naming with later JDKs, due to adoption of compatiblename by portable - Drop pversion which is a redundant alias for version now - Update tagging scripts to include signature checks and correctly handle gating - Add gating scripts to simplify obtaining results and waiving issues - ** This tarball is embargoed until 2026-07-21 @ 1pm PT. ** - Resolves: RHEL-212354 - Resolves: RHEL-188874 - Resolves: RHEL-212132 - Resolves: RHEL-212311 - Resolves: RHEL-212317 - Related: RHEL-212322 - Resolves: RHEL-212355 - Resolves: RHEL-212356 - Resolves: RHEL-212357 - Resolves: RHEL-212358 [1:1.8.0.502.b07-1.1] - Make headless own /usr/share/doc/java-1.8.0-openjdk - Make javadoc-zip own /usr/share/javadoc/java-1.8.0-openjdk - Resolves: RHEL-212322
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"cves": [
"CVE-2026-41254",
"CVE-2026-46968",
"CVE-2026-47010",
"CVE-2026-47021",
"CVE-2026-47027",
"CVE-2026-47057",
"CVE-2026-47058",
"CVE-2026-47059",
"CVE-2026-47063",
"CVE-2026-60147"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[1:1.8.0.502.b07-1.1.0.1]\n- Add Oracle vendor bug URL [Orabug: 34340155]\n\n[1:1.8.0.502.b07-1.1]\n- Update to 8u502-b07 (GA).\n- Update release notes for 8u502-b07.\n- Bump lcms2 version to 2.19.1 following JDK-8321489, JDK-8348110, JDK-8375065 JDK-8383354\n- Bump zlib version to 1.3.2 following JDK-8378631\n- Require tzdata 2026b due to upstream inclusion of JDK-8383175\n- Add attempted patch for JDK-8385876 to fix -Wnonnull build failure with s390x Zero on CentOS 9\n- Remove macro references in comments where possible (%dnl not compatible enough yet)\n- Move version information and core NVR definitions back towards the top of the file\n- Explictly define supported architectures\n- Specify portablerelease and rpmrelease (always 0 for portables) in the Release field\n- Make zone string debug output optional in TestTranslations\n- Change javadoc-zip to just own the top-level directory, not include the entire subtree\n- Update tagged versions to include 9.8.0-z 9.9.0.\n- Cleanup tagging and gating scripts to appease shellcheck:\n- * scripts/builds/build_vanilla.sh: Use an array to handle the varying arguments to rhpkg.\n- * scripts/builds/check_signatures.sh: Quote variable usage.\n- * scripts/builds/waive_issue.sh: Remove redundant 'test 'x'' usage.\n- * scripts/builds/waive_leapp_issue.sh: Likewise.\n- * scripts/builds/waive_rpminspect.sh: Likewise.\n- * scripts/builds/waive_usual_rpminspect.sh: Likewise and add missing WORKING_DIR variable.\n- * scripts/builds/waive_usual_tier0.sh: Remove redundant 'test 'x'' usage.\n- Obsolete old RHEL releases (8.2.0-z, 9.0.0-z, 9.7.0-z)\n- Sync the copy of the portable specfile with the latest update\n- Sync portable naming with later JDKs, due to adoption of compatiblename by portable\n- Drop pversion which is a redundant alias for version now\n- Update tagging scripts to include signature checks and correctly handle gating\n- Add gating scripts to simplify obtaining results and waiving issues\n- ** This tarball is embargoed until 2026-07-21 @ 1pm PT. **\n- Resolves: RHEL-212354\n- Resolves: RHEL-188874\n- Resolves: RHEL-212132\n- Resolves: RHEL-212311\n- Resolves: RHEL-212317\n- Related: RHEL-212322\n- Resolves: RHEL-212355\n- Resolves: RHEL-212356\n- Resolves: RHEL-212357\n- Resolves: RHEL-212358\n\n[1:1.8.0.502.b07-1.1]\n- Make headless own /usr/share/doc/java-1.8.0-openjdk\n- Make javadoc-zip own /usr/share/javadoc/java-1.8.0-openjdk\n- Resolves: RHEL-212322",
"id": "ELSA-2026-42877",
"ovalId": "oval:com.oracle.elsa:def:202642877",
"source": "oracle_linux",
"title": "ELSA-2026-42877: java-1.8.0-openjdk security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2026-42877.html"
}