SRU: backport openjdk-17 with some security fixes to hirsute

Bug #1925456 reported by Matthias Klose
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
openjdk-17 (Ubuntu)
Fix Released
Undecided
Unassigned
Hirsute
Fix Released
Undecided
Unassigned

Bug Description

while openjdk-17 is still a snapshot package, backport the new version with the security fixes to 21.04.

openjdk-17 (17~19-1) unstable; urgency=high

  * OpenJDK 17 snapshot, build 19.
    - Fix JDK-8250568: Less ambiguous processing (CVE-2021-2161).
    - Fix JDK-8249906: Enhance opening JARs (CVE-2021-2163).

 -- Matthias Klose <email address hidden> Thu, 22 Apr 2021 09:51:43 +0200

CVE References

Revision history for this message
Łukasz Zemczak (sil2100) wrote : Update Released

The verification of the Stable Release Update for openjdk-17 has completed successfully and the package is now being released to -updates. Subsequently, the Ubuntu Stable Release Updates Team is being unsubscribed and will not receive messages about this bug report. In the event that you encounter a regression using the package from -updates please report a new bug using ubuntu-bug and tag the bug report regression-update so we can easily find any regressions.

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package openjdk-17 - 17~19-1ubuntu1

---------------
openjdk-17 (17~19-1ubuntu1) hirsute-proposed; urgency=medium

  * SRU: LP: #1925456. Backport 17~19-1 to 21.04, including security fixes.

openjdk-17 (17~19-1) unstable; urgency=high

  * OpenJDK 17 snapshot, build 19.
    - Fix JDK-8250568: Less ambiguous processing (CVE-2021-2161).
    - Fix JDK-8249906: Enhance opening JARs (CVE-2021-2163).

 -- Matthias Klose <email address hidden> Thu, 22 Apr 2021 11:39:16 +0200

Changed in openjdk-17 (Ubuntu Hirsute):
status: New → Fix Released
Matthias Klose (doko)
Changed in openjdk-17 (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.