Описание
Security update for java-1_8_0-ibm
This update for java-1_8_0-ibm fixes the following issues:
Update to Java 8.0 Service Refresh 8 Fix Pack 45.
Security issues fixed:
-
Oracle April 15 2025 CPU (bsc#1242208)
- CVE-2025-21587: unauthorized access, deletion and modification of critical data via the JSSE component (bsc#1241274).
- CVE-2025-30691: unauthorized access to data via the Compiler component (bsc#1241275).
- CVE-2025-30698: unauthorized access to data and ability to cause a partial DoS via the 2D component (bsc#1241276).
-
IBM Security Update May 2025
- CVE-2025-4447: stack based buffer overflow in Eclipse OpenJ9 through modification of file that is read when the JVM starts (bsc#1243429).
Other changes and issues fixed:
-
Security:
- Avoid memory leak during aes cipher initialization operations for IBMJCEPlus and IBMJCEPlusProviders provider.
- Changing the default of the com.ibm.security.spnego.msinterop property from true to false.
- Deserializing a com.ibm.crypto.provider.rsaprivatecrtkey object causes a java.io.invalidobjectexception to be thrown.
- Failed to read private key from a JKS keystore, specified as JCEKS keystore.
- HTTPS channel binding support.
- Keytool listing PKCS12 keystore issue.
- On Linux systems, use gcc11.2 to compile IBM PKCS11 library.
- Support has been added to the IBM Java XMLDSigRI security provider for the EdDSA (Edwards-curve Digital Signature Algorithm).
- Updates to XDH Key Agreement, AESGCM Algorithms in IBMJCEPlus and IBMJCEPlusFIPS providers.
-
Class Libraries:
- Update timezone information to the latest tzdata2025a.
-
Java Virtual Machine:
- A SIGSEGV/GPF event received while processing verifyerror.
- Crash while resolving MethodHandleNatives.
- NoSuchMethodException or NoClassDefFoundError when loading classes.
-
JIT Compiler:
- Assert in the JIT Compiler, badILOp.
- Reduced MD5 performance.
Список пакетов
SUSE Linux Enterprise Server 12 SP5-LTSS
java-1_8_0-ibm-1.8.0_sr8.45-30.135.1
java-1_8_0-ibm-alsa-1.8.0_sr8.45-30.135.1
java-1_8_0-ibm-devel-1.8.0_sr8.45-30.135.1
java-1_8_0-ibm-plugin-1.8.0_sr8.45-30.135.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
java-1_8_0-ibm-1.8.0_sr8.45-30.135.1
java-1_8_0-ibm-alsa-1.8.0_sr8.45-30.135.1
java-1_8_0-ibm-devel-1.8.0_sr8.45-30.135.1
java-1_8_0-ibm-plugin-1.8.0_sr8.45-30.135.1
Ссылки
- Link for SUSE-SU-2025:01770-1
- E-Mail link for SUSE-SU-2025:01770-1
- SUSE Security Ratings
- SUSE Bug 1241274
- SUSE Bug 1241275
- SUSE Bug 1241276
- SUSE Bug 1242208
- SUSE Bug 1243429
- SUSE CVE CVE-2025-21587 page
- SUSE CVE CVE-2025-30691 page
- SUSE CVE CVE-2025-30698 page
- SUSE CVE CVE-2025-4447 page
Описание
unknown
Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-1.8.0_sr8.45-30.135.1
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-alsa-1.8.0_sr8.45-30.135.1
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-devel-1.8.0_sr8.45-30.135.1
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-plugin-1.8.0_sr8.45-30.135.1
Ссылки
- CVE-2025-21587
- SUSE Bug 1241274
Описание
unknown
Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-1.8.0_sr8.45-30.135.1
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-alsa-1.8.0_sr8.45-30.135.1
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-devel-1.8.0_sr8.45-30.135.1
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-plugin-1.8.0_sr8.45-30.135.1
Ссылки
- CVE-2025-30691
- SUSE Bug 1241275
Описание
unknown
Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-1.8.0_sr8.45-30.135.1
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-alsa-1.8.0_sr8.45-30.135.1
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-devel-1.8.0_sr8.45-30.135.1
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-plugin-1.8.0_sr8.45-30.135.1
Ссылки
- CVE-2025-30698
- SUSE Bug 1241274
- SUSE Bug 1241276
Описание
In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by modifying a file on disk that is read when the JVM starts.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-1.8.0_sr8.45-30.135.1
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-alsa-1.8.0_sr8.45-30.135.1
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-devel-1.8.0_sr8.45-30.135.1
SUSE Linux Enterprise Server 12 SP5-LTSS:java-1_8_0-ibm-plugin-1.8.0_sr8.45-30.135.1
Ссылки
- CVE-2025-4447
- SUSE Bug 1243429