Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 908243 - <dev-java/openjdk{,-jre-bin,-bin}-{8.372_p07,11.0.19_p7,17.0.7_p7}: multiple vulnerabilities (Oracle CPU Apr 2023)
Summary: <dev-java/openjdk{,-jre-bin,-bin}-{8.372_p07,11.0.19_p7,17.0.7_p7}: multiple ...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://openjdk.org/groups/vulnerabil...
Whiteboard: A3 [glsa+]
Keywords: PullRequest
Depends on: 877599 916121
Blocks: 908242
  Show dependency tree
 
Reported: 2023-06-10 17:10 UTC by John Helmert III
Modified: 2024-01-17 13:47 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-06-10 17:10:27 UTC
"These issues have been addressed, as applicable, in the following releases:
  8u372, 11.0.19, 17.0.7, and 20.0.1"

Please bump
Comment 1 Larry the Git Cow gentoo-dev 2023-06-26 21:36:46 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b97a717ae0db2b741381ff6f93b3c5572f726399

commit b97a717ae0db2b741381ff6f93b3c5572f726399
Author:     Georgy Yakovlev <gyakovlev@gentoo.org>
AuthorDate: 2023-06-26 21:25:48 +0000
Commit:     Georgy Yakovlev <gyakovlev@gentoo.org>
CommitDate: 2023-06-26 21:30:48 +0000

    dev-java/openjdk: add 17.0.7_p7
    
    Bug: https://bugs.gentoo.org/908243
    Signed-off-by: Georgy Yakovlev <gyakovlev@gentoo.org>

 dev-java/openjdk/Manifest                 |   1 +
 dev-java/openjdk/openjdk-17.0.7_p7.ebuild | 327 ++++++++++++++++++++++++++++++
 2 files changed, 328 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=61fe22eef1e2edec88d3f6f47d865dcf1c541612

commit 61fe22eef1e2edec88d3f6f47d865dcf1c541612
Author:     Georgy Yakovlev <gyakovlev@gentoo.org>
AuthorDate: 2023-06-26 21:15:31 +0000
Commit:     Georgy Yakovlev <gyakovlev@gentoo.org>
CommitDate: 2023-06-26 21:30:41 +0000

    dev-java/openjdk: add 11.0.19_p7
    
    Bug: https://bugs.gentoo.org/908243
    Signed-off-by: Georgy Yakovlev <gyakovlev@gentoo.org>

 dev-java/openjdk/Manifest                  |   1 +
 dev-java/openjdk/openjdk-11.0.19_p7.ebuild | 312 +++++++++++++++++++++++++++++
 2 files changed, 313 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=2275d6ea5a9baf5455b181abca45efa0a930b903

commit 2275d6ea5a9baf5455b181abca45efa0a930b903
Author:     Georgy Yakovlev <gyakovlev@gentoo.org>
AuthorDate: 2023-06-26 20:59:55 +0000
Commit:     Georgy Yakovlev <gyakovlev@gentoo.org>
CommitDate: 2023-06-26 21:30:36 +0000

    dev-java/openjdk: add 8.372_p07
    
    Bug: https://bugs.gentoo.org/908243
    Signed-off-by: Georgy Yakovlev <gyakovlev@gentoo.org>

 dev-java/openjdk/Manifest                 |   1 +
 dev-java/openjdk/openjdk-8.372_p07.ebuild | 239 ++++++++++++++++++++++++++++++
 2 files changed, 240 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=db312fa8cc307681cec30f786d8b622345a0ae89

commit db312fa8cc307681cec30f786d8b622345a0ae89
Author:     Georgy Yakovlev <gyakovlev@gentoo.org>
AuthorDate: 2023-06-26 20:41:37 +0000
Commit:     Georgy Yakovlev <gyakovlev@gentoo.org>
CommitDate: 2023-06-26 21:30:30 +0000

    dev-java/openjdk-jre-bin: add 17.0.7_p7
    
    Bug: https://bugs.gentoo.org/908243
    Signed-off-by: Georgy Yakovlev <gyakovlev@gentoo.org>

 dev-java/openjdk-jre-bin/Manifest                  |  1 +
 .../openjdk-jre-bin-17.0.7_p7.ebuild               | 83 ++++++++++++++++++++++
 2 files changed, 84 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=02ed968fb92ef359677e2b14543af38fa712f21a

commit 02ed968fb92ef359677e2b14543af38fa712f21a
Author:     Georgy Yakovlev <gyakovlev@gentoo.org>
AuthorDate: 2023-06-26 20:38:04 +0000
Commit:     Georgy Yakovlev <gyakovlev@gentoo.org>
CommitDate: 2023-06-26 21:30:25 +0000

    dev-java/openjdk-jre-bin: add 11.0.19_p7
    
    Bug: https://bugs.gentoo.org/908243
    Signed-off-by: Georgy Yakovlev <gyakovlev@gentoo.org>

 dev-java/openjdk-jre-bin/Manifest                  |  1 +
 .../openjdk-jre-bin-11.0.19_p7.ebuild              | 83 ++++++++++++++++++++++
 2 files changed, 84 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=113fe771c4d7b80d86ccee2b52c5f625d4f5c839

commit 113fe771c4d7b80d86ccee2b52c5f625d4f5c839
Author:     Georgy Yakovlev <gyakovlev@gentoo.org>
AuthorDate: 2023-06-26 20:19:42 +0000
Commit:     Georgy Yakovlev <gyakovlev@gentoo.org>
CommitDate: 2023-06-26 21:30:20 +0000

    dev-java/openjdk-jre-bin: add 8.372_p07
    
    Bug: https://bugs.gentoo.org/908243
    Signed-off-by: Georgy Yakovlev <gyakovlev@gentoo.org>

 dev-java/openjdk-jre-bin/Manifest                  |  1 +
 .../openjdk-jre-bin-8.372_p07.ebuild               | 82 ++++++++++++++++++++++
 2 files changed, 83 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=88ea92be9340cb09a6907e9689eea0563e0d98a8

commit 88ea92be9340cb09a6907e9689eea0563e0d98a8
Author:     Georgy Yakovlev <gyakovlev@gentoo.org>
AuthorDate: 2023-06-26 20:17:09 +0000
Commit:     Georgy Yakovlev <gyakovlev@gentoo.org>
CommitDate: 2023-06-26 21:30:13 +0000

    dev-java/openjdk-bin: add 17.0.7_p7
    
    Bug: https://bugs.gentoo.org/908243
    Signed-off-by: Georgy Yakovlev <gyakovlev@gentoo.org>

 dev-java/openjdk-bin/Manifest                     |   7 ++
 dev-java/openjdk-bin/openjdk-bin-17.0.7_p7.ebuild | 136 ++++++++++++++++++++++
 2 files changed, 143 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ecac4bb16a3dba16922b76884e0f76a4fb45970c

commit ecac4bb16a3dba16922b76884e0f76a4fb45970c
Author:     Georgy Yakovlev <gyakovlev@gentoo.org>
AuthorDate: 2023-06-26 19:50:26 +0000
Commit:     Georgy Yakovlev <gyakovlev@gentoo.org>
CommitDate: 2023-06-26 21:30:07 +0000

    dev-java/openjdk-bin: add 11.0.19_p7
    
    Bug: https://bugs.gentoo.org/908243
    Signed-off-by: Georgy Yakovlev <gyakovlev@gentoo.org>

 dev-java/openjdk-bin/Manifest                      |   6 +
 dev-java/openjdk-bin/openjdk-bin-11.0.19_p7.ebuild | 135 +++++++++++++++++++++
 2 files changed, 141 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=3c0dcbe03a09198ffb431b9c7bd6d3496367bd2b

commit 3c0dcbe03a09198ffb431b9c7bd6d3496367bd2b
Author:     Georgy Yakovlev <gyakovlev@gentoo.org>
AuthorDate: 2023-06-26 19:29:30 +0000
Commit:     Georgy Yakovlev <gyakovlev@gentoo.org>
CommitDate: 2023-06-26 21:29:51 +0000

    dev-java/openjdk-bin: add 8.372_p07
    
    Bug: https://bugs.gentoo.org/908243
    Signed-off-by: Georgy Yakovlev <gyakovlev@gentoo.org>

 dev-java/openjdk-bin/Manifest                     |   6 +
 dev-java/openjdk-bin/openjdk-bin-8.372_p07.ebuild | 131 ++++++++++++++++++++++
 2 files changed, 137 insertions(+)
Comment 2 Georgy Yakovlev archtester gentoo-dev 2023-06-26 21:39:29 UTC
let's bake it for couple weeks and stablereq.

ajak - if I'm not around - feel free to file stablereq too, no objections.
Comment 3 Larry the Git Cow gentoo-dev 2023-10-26 07:26:23 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6eba331a8c2eda46cef39f0d919579b763e0a670

commit 6eba331a8c2eda46cef39f0d919579b763e0a670
Author:     Volkmar W. Pogatzki <gentoo@pogatzki.net>
AuthorDate: 2023-10-25 19:06:49 +0000
Commit:     Miroslav Šulc <fordfrog@gentoo.org>
CommitDate: 2023-10-26 07:25:36 +0000

    dev-java/openjdk-jre-bin: drop versions
    
    Bug: https://bugs.gentoo.org/908243
    Signed-off-by: Volkmar W. Pogatzki <gentoo@pogatzki.net>
    Closes: https://github.com/gentoo/gentoo/pull/33513
    Signed-off-by: Miroslav Šulc <fordfrog@gentoo.org>

 dev-java/openjdk-jre-bin/Manifest                  |  6 --
 .../openjdk-jre-bin-11.0.18_p10.ebuild             | 83 ----------------------
 .../openjdk-jre-bin-11.0.19_p7.ebuild              | 83 ----------------------
 .../openjdk-jre-bin-17.0.6_p10.ebuild              | 83 ----------------------
 .../openjdk-jre-bin-17.0.7_p7.ebuild               | 83 ----------------------
 .../openjdk-jre-bin-8.362_p09.ebuild               | 82 ---------------------
 .../openjdk-jre-bin-8.372_p07.ebuild               | 82 ---------------------
 7 files changed, 502 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e261cac9590c49e4a96fb8628e489b95ff4f1382

commit e261cac9590c49e4a96fb8628e489b95ff4f1382
Author:     Volkmar W. Pogatzki <gentoo@pogatzki.net>
AuthorDate: 2023-10-25 19:04:22 +0000
Commit:     Miroslav Šulc <fordfrog@gentoo.org>
CommitDate: 2023-10-26 07:25:36 +0000

    dev-java/openjdk-bin: drop versions
    
    Bug: https://bugs.gentoo.org/908243
    Signed-off-by: Volkmar W. Pogatzki <gentoo@pogatzki.net>
    Signed-off-by: Miroslav Šulc <fordfrog@gentoo.org>

 dev-java/openjdk-bin/Manifest                      |  38 ------
 .../openjdk-bin/openjdk-bin-11.0.18_p10.ebuild     | 135 --------------------
 dev-java/openjdk-bin/openjdk-bin-11.0.19_p7.ebuild | 135 --------------------
 dev-java/openjdk-bin/openjdk-bin-17.0.6_p10.ebuild | 136 ---------------------
 dev-java/openjdk-bin/openjdk-bin-17.0.7_p7.ebuild  | 136 ---------------------
 dev-java/openjdk-bin/openjdk-bin-8.362_p09.ebuild  | 131 --------------------
 dev-java/openjdk-bin/openjdk-bin-8.372_p07.ebuild  | 131 --------------------
 7 files changed, 842 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ba1ebbcac4b2786b81587f19f2093b06cf07a6b9

commit ba1ebbcac4b2786b81587f19f2093b06cf07a6b9
Author:     Volkmar W. Pogatzki <gentoo@pogatzki.net>
AuthorDate: 2023-10-25 18:58:01 +0000
Commit:     Miroslav Šulc <fordfrog@gentoo.org>
CommitDate: 2023-10-26 07:25:30 +0000

    dev-java/openjdk: drop versions
    
    Bug: https://bugs.gentoo.org/908243
    Signed-off-by: Volkmar W. Pogatzki <gentoo@pogatzki.net>
    Signed-off-by: Miroslav Šulc <fordfrog@gentoo.org>

 dev-java/openjdk/Manifest                     |   6 -
 dev-java/openjdk/openjdk-11.0.18_p10.ebuild   | 312 ------------------------
 dev-java/openjdk/openjdk-11.0.19_p7.ebuild    | 312 ------------------------
 dev-java/openjdk/openjdk-17.0.6_p10-r1.ebuild | 329 --------------------------
 dev-java/openjdk/openjdk-17.0.6_p10.ebuild    | 327 -------------------------
 dev-java/openjdk/openjdk-17.0.7_p7.ebuild     | 327 -------------------------
 dev-java/openjdk/openjdk-8.362_p09.ebuild     | 239 -------------------
 dev-java/openjdk/openjdk-8.372_p07.ebuild     | 239 -------------------
 8 files changed, 2091 deletions(-)
Comment 4 Larry the Git Cow gentoo-dev 2024-01-17 13:45:37 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=192b729d81f588010b67c1e39e06aa02c513b126

commit 192b729d81f588010b67c1e39e06aa02c513b126
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2024-01-17 13:45:06 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2024-01-17 13:45:28 +0000

    [ GLSA 202401-25 ] OpenJDK: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/859376
    Bug: https://bugs.gentoo.org/859400
    Bug: https://bugs.gentoo.org/877597
    Bug: https://bugs.gentoo.org/891323
    Bug: https://bugs.gentoo.org/908243
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202401-25.xml | 99 ++++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 99 insertions(+)