Summary: | <dev-java/openjdk{,-jre-bin,-bin}-{8.312_p07, 11.0.13_p8}: multiple vulnerabilities (CVE-2021-{2341,2369,2388,2432}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | gyakovlev, java, kfm |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://www.oracle.com/security-alerts/cpujul2021.html#AppendixJAVA | ||
Whiteboard: | B3 [glsa+] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 827554 | ||
Bug Blocks: | 803602, 819537 |
Description
John Helmert III
2021-07-24 01:33:18 UTC
openjdk-11 stable and is affected. will be bumping to 11.0.12 today. openjdk-8.282 we do not have at all, but it also gets a bump to 8.302 today. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ac28226c18975c211b7c5138980d9fc68dce9ebc commit ac28226c18975c211b7c5138980d9fc68dce9ebc Author: Georgy Yakovlev <gyakovlev@gentoo.org> AuthorDate: 2021-07-27 01:13:36 +0000 Commit: Georgy Yakovlev <gyakovlev@gentoo.org> CommitDate: 2021-07-27 01:23:54 +0000 dev-java/openjdk: add 11.0.12_p7 Bug: https://bugs.gentoo.org/803605 Signed-off-by: Georgy Yakovlev <gyakovlev@gentoo.org> dev-java/openjdk/Manifest | 1 + dev-java/openjdk/openjdk-11.0.12_p7.ebuild | 275 +++++++++++++++++++++++++++++ 2 files changed, 276 insertions(+) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=be4e238f48ff45815c2a5a37b09edec7c0030118 commit be4e238f48ff45815c2a5a37b09edec7c0030118 Author: Georgy Yakovlev <gyakovlev@gentoo.org> AuthorDate: 2021-07-27 01:05:14 +0000 Commit: Georgy Yakovlev <gyakovlev@gentoo.org> CommitDate: 2021-07-27 01:23:52 +0000 dev-java/openjdk: add 8.302_p08 Bug: https://bugs.gentoo.org/803605 Signed-off-by: Georgy Yakovlev <gyakovlev@gentoo.org> dev-java/openjdk/Manifest | 16 ++ dev-java/openjdk/files/openjdk-8.env.sh | 2 +- dev-java/openjdk/openjdk-8.302_p08.ebuild | 253 ++++++++++++++++++++++++++++++ 3 files changed, 270 insertions(+), 1 deletion(-) also adoptopenjdk moves to eclipse and re-branding as temurin/adoptium, we do not have -bin packages yet as they haven't published them yet. Thanks! Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. Package list is empty or all packages have requested keywords. cleanup done Thanks! GLSA request filed The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=e1a6765fc7cb3c5afe0b95463f49a9924ef37cab commit e1a6765fc7cb3c5afe0b95463f49a9924ef37cab Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2022-09-07 02:52:52 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2022-09-07 02:58:08 +0000 [ GLSA 202209-05 ] OpenJDK: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/784611 Bug: https://bugs.gentoo.org/803605 Bug: https://bugs.gentoo.org/831446 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: John Helmert III <ajak@gentoo.org> glsa-202209-05.xml | 153 +++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 153 insertions(+) GLSA released, all done! |