java-11-openjdk-11.0.21.0.9-2.el8
エラータID: AXSA:2023-6545:24
The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit.
Security Fix(es):
* OpenJDK: certificate path validation issue during client authentication (8309966) (CVE-2023-22081)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* Additional validity checks in the handling of Zip64 files, JDK-8302483, were introduced in the 11.0.20 release of OpenJDK, causing the use of some valid zip files to now fail with an error. This release, 11.0.20.1, allows for zero-length headers and additional padding produced by some Zip64 creation tools. With both releases, the checks can be disabled using -Djdk.util.zip.disableZip64ExtraFieldValidation=true. (RHBZ#2237170)
* A maximum signature file size property, jdk.jar.maxSignatureFileSize, was introduced in the 11.0.20 release of OpenJDK by JDK-8300596, with a default of 8 MB. This default proved to be too small for some JAR files. This release, 11.0.20.1, increases it to 16 MB.
* The serviceability agent would print an exception when encountering null addresses while producing thread dumps. These null values are now handled appropriately. (JDK-8243210, RHEL-2763)
* The /usr/bin/jfr alternative is now owned by the java-11-openjdk package (RHEL-13559)
* The jcmd tool is now provided by the java-11-openjdk-headless package, rather than java-11-openjdk-devel, to make it more accessible (RHEL-13566)
CVE-2023-22081
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf, 11.0.20, 17.0.8, 21; Oracle GraalVM for JDK: 17.0.8 and 21. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Java SE, Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Update packages.
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf, 11.0.20, 17.0.8, 21; Oracle GraalVM for JDK: 17.0.8 and 21. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Java SE, Oracle GraalVM for JDK. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
N/A
SRPMS
- java-11-openjdk-11.0.21.0.9-2.el8.src.rpm
MD5: ade42dee68ddf450aad5d90623f19323
SHA-256: b37c7e49eb57118f20a414088aed515be03dcbdfe08b1a4f19e12bff21f1b66d
Size: 68.38 MB
Asianux Server 8 for x86_64
- java-11-openjdk-11.0.21.0.9-2.el8.x86_64.rpm
MD5: d251db215cc26d4873d826a775567a86
SHA-256: 1268d584080202d0404e43109bd4fd2bd6a6315eb404c77b937555d108fca4ff
Size: 473.60 kB - java-11-openjdk-demo-11.0.21.0.9-2.el8.x86_64.rpm
MD5: ce5cc2fcab8da3387c3d0cc2b7d88c1a
SHA-256: 9cba263f488bd7ff97ffa73946a844748b61fbd3ca18e8042d768045fb9f21ec
Size: 4.39 MB - java-11-openjdk-demo-fastdebug-11.0.21.0.9-2.el8.x86_64.rpm
MD5: 280de79314884542ee451ca63feca084
SHA-256: 25fc86147a1d4dc85895041bcb6a877f16bf02f7a20a76fd7abca9bb49f7d880
Size: 4.39 MB - java-11-openjdk-demo-slowdebug-11.0.21.0.9-2.el8.x86_64.rpm
MD5: 6a1998fcb276b06f64121331d6c0edb0
SHA-256: f661c03b5abc0ed715b8d547d93d6733cb5f428888e558f68a4df011ecef06e8
Size: 4.39 MB - java-11-openjdk-devel-11.0.21.0.9-2.el8.x86_64.rpm
MD5: a8fbf8a8913d22d1db02a7bea9458c03
SHA-256: aa404d11c4b0ab1eb21148e571fae3bba0e8c60e710db6c9f481e7a8fb3a7a81
Size: 3.39 MB - java-11-openjdk-devel-fastdebug-11.0.21.0.9-2.el8.x86_64.rpm
MD5: 0ac6fe0e321ba28f0535be782f567fed
SHA-256: 42c17739e278c5f6df872d13476bba40e6da9ff3d2bdd28f84befb82de80842c
Size: 3.39 MB - java-11-openjdk-devel-slowdebug-11.0.21.0.9-2.el8.x86_64.rpm
MD5: 09f956077c3b91efe044edf7ac6d52d4
SHA-256: 25620e11c53ef414e0c4bc0ca0ae64081c9142c5129a7164316a05d481a5bd09
Size: 3.39 MB - java-11-openjdk-fastdebug-11.0.21.0.9-2.el8.x86_64.rpm
MD5: 6a56d8d097c4c5b8332c50bbd5673d6c
SHA-256: 5f6e0a66374e7986e689628e2e6857c5f782a545ca23d7d1d971504d2d6314d7
Size: 486.81 kB - java-11-openjdk-headless-11.0.21.0.9-2.el8.x86_64.rpm
MD5: 59a4646d001edfda74cf304a00832fb6
SHA-256: 306a6900aa915f62af41c912f5bee9e8fccebcdade0462e57022b50f848fa3cb
Size: 41.61 MB - java-11-openjdk-headless-fastdebug-11.0.21.0.9-2.el8.x86_64.rpm
MD5: 5b41e6a5e6920f73e95477207021ddab
SHA-256: 2acc12f455055599f28922b987ca53c9e3f5b94122f7ab8e614015553496fce7
Size: 46.61 MB - java-11-openjdk-headless-slowdebug-11.0.21.0.9-2.el8.x86_64.rpm
MD5: e8c341024810f61ca6a9ef179f2f61d4
SHA-256: 281081539888501d5bf8fb499c3f32c47f1bff985b4c7294432fa4d909ffedee
Size: 46.08 MB - java-11-openjdk-javadoc-11.0.21.0.9-2.el8.x86_64.rpm
MD5: fb274c8f85e2d68b1d3a82d9e5908118
SHA-256: 39aacd38d2989c152046a195363a8f55f78f619e13a08d14370ccd6e0b11eae3
Size: 16.00 MB - java-11-openjdk-javadoc-zip-11.0.21.0.9-2.el8.x86_64.rpm
MD5: 6feb4f1fc5180fa12c4f23cc822d76cf
SHA-256: 566d9345bfa49e3c700dd99b6ba125cc4d1fe1cdf78236259b51f8bde026037e
Size: 42.10 MB - java-11-openjdk-jmods-11.0.21.0.9-2.el8.x86_64.rpm
MD5: 747842619e24d8bdbdb3fe8b11b9fba0
SHA-256: 9bd17fe525af410651cb069aa1eaef39da751ebe6c15f233519a1e07a398f7eb
Size: 342.08 MB - java-11-openjdk-jmods-fastdebug-11.0.21.0.9-2.el8.x86_64.rpm
MD5: debeea84e507c3fc00094bc57e378746
SHA-256: 43fe9bb2eec2a213db5387637efaf6ba99af36c751c85f7042fcbb336a11b541
Size: 297.11 MB - java-11-openjdk-jmods-slowdebug-11.0.21.0.9-2.el8.x86_64.rpm
MD5: bbda1ad97789bc5ff8c1a790e2f5cdeb
SHA-256: 21c616647748a3f7fc219bda1b0899ed98a61629d87ba35c8fd39177ccfcbaed
Size: 229.45 MB - java-11-openjdk-slowdebug-11.0.21.0.9-2.el8.x86_64.rpm
MD5: f4db7e7933788c939319ecbfc7c1e15f
SHA-256: ade2803a0afb921bd7d0de9e1dc13f8a241d442559829d69b0bb4d9608edb111
Size: 461.01 kB - java-11-openjdk-src-11.0.21.0.9-2.el8.x86_64.rpm
MD5: be1a1568777a4c333007e1fc97553307
SHA-256: c04756f53838de095e163cfc481edc5b240c4076eb1a718c01e9b474cdd99eb1
Size: 50.52 MB - java-11-openjdk-src-fastdebug-11.0.21.0.9-2.el8.x86_64.rpm
MD5: 4f9af8926693a98665e878a0fc658a05
SHA-256: 82094af50dba1e921564500786995c523e3369a1bf1263c5efde0452e2abd15e
Size: 50.53 MB - java-11-openjdk-src-slowdebug-11.0.21.0.9-2.el8.x86_64.rpm
MD5: a9600d1c6f1c1a2eb4b85451359e47ba
SHA-256: bb6d39a398f326ea26fafead89b384ca50a61702d6034b8b61568784f202cebf
Size: 50.53 MB - java-11-openjdk-static-libs-11.0.21.0.9-2.el8.x86_64.rpm
MD5: 3119dce58a62939a95daba334d8e5c1f
SHA-256: c9c5dcb1b2633908598aa13de74ce12dcd2ddbfcdc225239058cd46143c91837
Size: 35.46 MB - java-11-openjdk-static-libs-fastdebug-11.0.21.0.9-2.el8.x86_64.rpm
MD5: 28f8e672945a5ba3fd191586131c05cd
SHA-256: c3a5ae70f43a57292bed713d7ad4628655966f7e74cdf9c923b1d93ec003e756
Size: 35.72 MB - java-11-openjdk-static-libs-slowdebug-11.0.21.0.9-2.el8.x86_64.rpm
MD5: 6576b06c169d4d59d13aaaff67ddcaa9
SHA-256: 7f45c8a5c51e3ee870f5c230a8cbd8a3d95c81602dfbab70f5bd31e6a1ebde6a
Size: 31.07 MB