Описание
ELSA-2026-55787: java-21-openjdk security update (MODERATE)
[1:21.0.12.1.1-1.1.0.1]
- Add Oracle vendor bug URL [Orabug: 34340155]
[1:21.0.12.1.1-1.1]
- Update to jdk-21.0.12.1+1 (GA)
- Update release notes to 21.0.12.1+1
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-08-18 @ 1pm PT. **
- Resolves: RHEL-235610
[1:21.0.12.0.8-2.1]
- Add CVEs to NEWS file
- Update to tarball with final changeset ID
- Sync the copy of the portable specfile with the latest update
- Related: RHEL-188853
[1:21.0.12.0.8-1.1]
- Update to jdk-21.0.12+8 (GA)
- Update release notes to 21.0.12+8
- Bump freetype version to 2.14.3 following JDK-8385390
- Bump giflib version to 6.1.3 following JDK-8384902
- Bump HarfBuzz version to 14.2.0 following JDK-8385490
- Bump lcms2 version to 2.19.1 following JDK-8375065 & JDK-8383354
- Bump libpng version to 1.6.58 following JDK-8384495
- Update tagging scripts to include signature checks and correctly handle gating
- Update tagged versions to include 9.8.0-z, 9.9.0, 10.2-z & 10.3.
- Add gating scripts to simplify obtaining results and waiving issues
- Cleanup tagging and gating scripts to appease shellcheck:
-
- scripts/builds/build_vanilla.sh: Use an array to handle the varying arguments to rhpkg.
-
- scripts/builds/check_signatures.sh: Quote variable usage.
-
- scripts/builds/waive_issue.sh: Remove redundant 'test 'x'' usage.
-
- scripts/builds/waive_leapp_issue.sh: Likewise.
-
- scripts/builds/waive_rpminspect.sh: Likewise.
-
- scripts/builds/waive_usual_rpminspect.sh: Likewise and add missing WORKING_DIR variable.
-
- scripts/builds/waive_usual_tier0.sh: Remove redundant 'test 'x'' usage.
- Remove macro references in comments where possible (%dnl not compatible enough yet)
- Move version information and core NVR definitions back towards the top of the file
- Specify portablerelease and rpmrelease (always 0 for portables) in the Release field
- Obsolete old RHEL releases (9.7.0-z, 10.1-z)
- Make zone string debug output optional in TestTranslations
- Change javadoc-zip to just own the top-level directory, not include the entire subtree
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-07-21 @ 1pm PT. **
- Resolves: RHEL-212331
- Resolves: RHEL-212333
- Resolves: RHEL-212335
- Resolves: RHEL-212351
- Resolves: RHEL-212337
- Resolves: RHEL-188853
- Resolves: RHEL-212344
- Resolves: RHEL-212346
- Related: RHEL-212353
[1:21.0.11.0.10-1.2]
- Disable abidiff inspection in rpminspect.yaml to avoid an out-of-memory error on the CentOS test farm
- See: https://docs.testing-farm.io/Testing%20Farm/0.1/errors.html#TFE-1
- Do not overwrite slowdebug __provides_exclude_from and __requires_exclude_from regexps
- Make headless own /usr/share/doc/java-1.8.0-openjdk
- Make javadoc-zip own /usr/share/javadoc/java-1.8.0-openjdk
- Resolves: RHEL-212350
- Resolves: RHEL-212352
- Resolves: RHEL-212353
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
java-21-openjdk-demo-fastdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-demo-slowdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-devel-fastdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-devel-slowdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-fastdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-headless-fastdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-headless-slowdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-jmods-fastdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-jmods-slowdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-slowdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-src-fastdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-src-slowdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-static-libs-fastdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-static-libs-slowdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-demo
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-devel
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-headless
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-javadoc
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-javadoc-zip
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-jmods
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-src
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-static-libs
21.0.12.1.1-1.1.0.1.el8
Oracle Linux x86_64
java-21-openjdk-demo-fastdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-demo-slowdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-devel-fastdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-devel-slowdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-fastdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-headless-fastdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-headless-slowdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-jmods-fastdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-jmods-slowdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-slowdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-src-fastdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-src-slowdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-static-libs-fastdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-static-libs-slowdebug
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-demo
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-devel
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-headless
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-javadoc
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-javadoc-zip
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-jmods
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-src
21.0.12.1.1-1.1.0.1.el8
java-21-openjdk-static-libs
21.0.12.1.1-1.1.0.1.el8
Связанные CVE
Связанные уязвимости
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vec...