Bug 56776 - openjdk-11: Multiple issues (5.0)
Summary: openjdk-11: Multiple issues (5.0)
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Security updates
Version: UCS 5.0
Hardware: All Linux
: P3 normal
Target Milestone: UCS 5.0-5-errata
Assignee: Quality Assurance
QA Contact: Iván.Delgado
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-10-30 12:39 CET by Quality Assurance
Modified: 2023-11-02 14:54 CET (History)
1 user (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID:
Max CVSS v3 score: 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2023-10-30 12:39:33 CET
New Debian openjdk-11 11.0.21+9-1~deb10u1 fixes:
This update addresses the following issue:
11.0.21+9-1~deb10u1 (Mon, 23 Oct 2023 08:32:45 +0200)
* Non-maintainer upload by the LTS Team.
* Backport to buster.
11.0.21+9-1 (Wed, 18 Oct 2023 09:28:04 +0200)
* OpenJDK 11.0.21 release, build 9. - CVE-2023-22081. - Release notes:  https://www.oracle.com/java/technologies/javase/11-0-21-relnotes.html#R11_0_21
[ Vladimir Petko ]
* d/test: update problemlist.
* d/p: drop exclude-broken-tests.patch.
* d/p/reproducible-properties-timestamp.diff: use the privileged action to  read the system property (JDK-8272157, 914278).
[ Matthias Klose ]
* Build using GCC 13 on development versions.
[ Pushkar Kulkarni ]
* Handle limited ECC capabilities of NSS on older releases.
11.0.21~4ea-1 (Thu, 24 Aug 2023 12:53:49 +0200)
* OpenJDK 11.0.21 release, build 4 (early access).
* d/copyright: remove liblcms from excluded files.
* Refresh patch for 11.0.21+2 ea.
* d/t/jtreg-autopkgtest.{sh,in}: JDK-8232153 - set NSS_DEFAULT_DB_TYPE to let  sun/security/pkcs11/Secmod/AddTrustedCert.java pass.
* Explicitly configure --without-jtreg with the nocheck profile
Comment 1 Quality Assurance univentionstaff 2023-10-30 13:00:42 CET
--- mirror/ftp/pool/main/o/openjdk-11/openjdk-11_11.0.20+8-1~deb10u1.dsc
+++ apt/ucs_5.0-0-errata5.0-5/source/openjdk-11_11.0.21+9-1~deb10u1.dsc
@@ -1,3 +1,40 @@
+11.0.21+9-1~deb10u1 [Mon, 23 Oct 2023 08:32:45 +0200] Emilio Pozuelo Monfort <pochu@debian.org>:
+
+  * Non-maintainer upload by the LTS Team.
+  * Backport to buster.
+
+11.0.21+9-1 [Wed, 18 Oct 2023 09:28:04 +0200] Matthias Klose <doko@ubuntu.com>:
+
+  * OpenJDK 11.0.21 release, build 9.
+    - CVE-2023-22081.
+    - Release notes:
+      https://www.oracle.com/java/technologies/javase/11-0-21-relnotes.html#R11_0_21
+
+  [ Vladimir Petko ]
+  * d/test: update problemlist.
+  * d/p: drop exclude-broken-tests.patch.
+  * d/p/reproducible-properties-timestamp.diff: use the privileged action
+    to read the system property (JDK-8272157, 914278).
+
+  [ Matthias Klose ]
+  * Build using GCC 13 on development versions.
+
+  [ Pushkar Kulkarni ]
+  * Handle limited ECC capabilities of NSS on older releases.
+
+11.0.21~4ea-1 [Thu, 24 Aug 2023 12:53:49 +0200] Matthias Klose <doko@ubuntu.com>:
+
+  * OpenJDK 11.0.21 release, build 4 (early access).
+
+  [ Vladimir Petko ]
+  * d/copyright: remove liblcms from excluded files.
+  * Refresh patch for 11.0.21+2 ea.
+  * d/t/jtreg-autopkgtest.{sh,in}: JDK-8232153 - set NSS_DEFAULT_DB_TYPE
+    to let sun/security/pkcs11/Secmod/AddTrustedCert.java pass.
+
+  [ Matthias Klose ]
+  * Explicitly configure --without-jtreg with the nocheck profile
+
 11.0.20+8-1~deb10u1 [Mon, 18 Sep 2023 19:14:04 +0200] Emilio Pozuelo Monfort <pochu@debian.org>:
 
   * Non-maintainer upload by the LTS Team.

<http://piuparts.knut.univention.de/5.0-5/#4611399974709017125>
Comment 2 Philipp Hahn univentionstaff 2023-11-02 13:11:07 CET
OK: bug
OK: yaml
OK: announce_errata
OK: patch
~OK: piuparts
 fails for "openjdk-11-source", which depends on a broken version of
 "ca-certificates-java", which itself depends again on OpenJDK → cirtular
 dependency
 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929685

[5.0-5] 25f4f8b65c Bug #56776: openjdk-11 11.0.21+9-1~deb10u1
 doc/errata/staging/openjdk-11.yaml | 26 +++-----------------------
 1 file changed, 3 insertions(+), 23 deletions(-)

[5.0-5] 7a36757ed4 Bug #56776: openjdk-11 11.0.21+9-1~deb10u1
 doc/errata/staging/openjdk-11.yaml | 33 +++++++++++++++++++++++++++++++++
 1 file changed, 33 insertions(+)