Fedora Linux 8566 Published by

A java-11-openjdk security update has been released for Fedora 30.



--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2020-d735a887d1
2020-02-08 01:36:33.446540
--------------------------------------------------------------------------------

Name : java-11-openjdk
Product : Fedora 30
Version : 11.0.6.10
Release : 0.fc30
URL :   http://openjdk.java.net/
Summary : OpenJDK Runtime Environment 11
Description :
The OpenJDK runtime environment.

--------------------------------------------------------------------------------
Update Information:

Update to the January 2020 CPU release 11.0.6. See:
  http://mail.openjdk.java.net/pipermail/jdk-updates-dev/2020-January/002374.html
  https://openjdk.java.net/groups/vulnerability/advisories/2020-01-14
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jan 11 2020 Andrew John Hughes - 1:11.0.6.10-0
- Update to shenandoah-jdk-11.0.6+10 (GA)
- Add support for jfr binary.
- Add JDK-8236039 backport to resolve OpenShift blocker.
- Add JDK-8224851 backport to resolve AArch64 compiler issues.
* Wed Oct 9 2019 Andrew Hughes - 1:11.0.5.10-0
- Update to shenandoah-jdk-11.0.5+10 (GA)
- Switch to GA mode for final release.
* Mon Oct 7 2019 Andrew Hughes - 1:11.0.5.9-0.0.ea
- Update to shenandoah-jdk-11.0.5+9 (EA)
* Tue Aug 27 2019 Andrew Hughes - 1:11.0.5.2-0.2.ea
- Update generate_source_tarball.sh script to use the PR3751 patch and retain the secp256k1 curve.
- Regenerate source tarball using the updated script and add the -'4curve' suffix.
- PR3751 includes the changes in the PR1834/RH1022017 patch which is removed.
* Sat Aug 24 2019 Andrew John Hughes - 1:11.0.5.2-0.1.ea
- Update to shenandoah-jdk-11.0.5+2 (EA)
* Mon Aug 12 2019 Andrew Hughes - 1:11.0.5.1-0.1.ea
- Update to shenandoah-jdk-11.0.5+1 (EA)
- Switch to EA mode for 11.0.5 pre-release builds.
* Thu Aug 8 2019 Andrew Hughes - 1:11.0.4.11-4
- Switch to in-tree SunEC code, dropping NSS runtime dependencies and patches to link against it.
* Fri Jul 26 2019 Andrew John Hughes - 1:11.0.4.11-3
- Drop unnecessary build requirement on gtk3-devel, as OpenJDK searches for Gtk+ at runtime.
- Add missing build requirement for libXrender-devel, previously masked by Gtk3+ dependency
- Add missing build requirement for libXrandr-devel, previously masked by Gtk3+ dependency
- fontconfig build requirement should be fontconfig-devel, previously masked by Gtk3+ dependency
* Fri Jul 26 2019 Severin Gehwolf - 1:11.0.4.11-2
- Rebuild with itself as boot JDK.
* Fri Jul 26 2019 Severin Gehwolf - 1:11.0.4.11-1
- Remove -fno-tree-ch workaround for i686 as the root cause has been
fixed with 11.0.4+9.
- Resolves RHBZ#1683095
* Tue Jul 9 2019 Andrew Hughes - 1:11.0.4.11-0
- Update to shenandoah-jdk-11.0.4+11 (GA)
- Switch to GA mode for final release.
* Mon Jul 8 2019 Andrew Hughes - 1:11.0.4.10-0.2.ea
- Obsolete javadoc-slowdebug and javadoc-slowdebug-zip packages via javadoc and javadoc-zip respectively.
* Mon Jul 8 2019 Andrew Hughes - 1:11.0.4.10-0.1.ea
- Update to shenandoah-jdk-11.0.4+10 (EA)
* Sun Jun 30 2019 Andrew John Hughes - 1:11.0.4.2-0.1.ea
- Update to shenandoah-jdk-11.0.4+2 (EA)
* Fri Jun 21 2019 Severin Gehwolf - 1:11.0.4.2-0.1.ea
- Package jspawnhelper (see JDK-8220360).
* Fri Jun 21 2019 Severin Gehwolf - 1:11.0.3.7-6
- Include 'ea' designator in Release when appropriate.
* Wed May 22 2019 Andrew Hughes - 1:11.0.3.7-6
- Handle milestone as variables so we can alter it easily and set the docs zip filename appropriately.
* Tue May 14 2019 Severin Gehwolf - 1:11.0.3.7-5
- Bump release for rebuild.
* Fri May 10 2019 Severin Gehwolf - 1:11.0.3.7-4
- Add -fno-tree-ch in order to work around GCC 9 issue on
i686.
- Resolves: RHBZ#1683095
* Thu Apr 25 2019 Severin Gehwolf - 1:11.0.3.7-3
- Don't produce javadoc/javadoc-zip sub packages for the
debug variant build.
- Don't perform a bootcycle build for the debug variant build.
* Wed Apr 24 2019 Severin Gehwolf - 1:11.0.3.7-2
- Don't generate lib-style requires for -slowdebug subpackages.
- Resolves: RHBZ#1702379
* Tue Apr 23 2019 Severin Gehwolf - 1:11.0.3.7-1
- Fix requires/provides for the non-system JDK case. JDK 11
isn't a system JDK at this point.
- Resolves: RHBZ#1702324
* Sun Apr 7 2019 Andrew Hughes - 1:11.0.3.7-0
- Update to shenandoah-jdk-11.0.3+7 (April 2019 GA)
* Sat Apr 6 2019 Andrew Hughes - 1:11.0.3.6-0
- Update to shenandoah-jdk-11.0.3+6 (April 2019 EA)
- Drop JDK-8210416/RH1632174 applied upstream.
- Drop JDK-8210425/RH1632174 applied upstream.
- Drop JDK-8210647/RH1632174 applied upstream.
- Drop JDK-8210761/RH1632174 applied upstream.
- Drop JDK-8210703/RH1632174 applied upstream.
- Add cast to resolve s390 ambiguity in call to log2_intptr
* Thu Mar 21 2019 Severin Gehwolf - 1:11.0.2.7-9
- Add patch for RH1566890
* Wed Mar 20 2019 Peter Robinson 1:11.0.2.7-8
- Drop chkconfig dep, 1.7 shipped in f24
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #1795322 - Update OpenJDK to 11.0.6
  https://bugzilla.redhat.com/show_bug.cgi?id=1795322
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2020-d735a887d1' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys