New in release OpenJDK 11.0.14 (2022-01-18):

Live versions of these release notes can be found at:

Security fixes

  • JDK-8217375: jarsigner breaks old signature with long lines in manifest
  • JDK-8251329: (zipfs) Files.walkFileTree walks infinitely if zip has dir named "." inside
  • JDK-8264934, CVE-2022-21248: Enhance cross VM serialization
  • JDK-8268488: More valuable DerValues
  • JDK-8268494: Better inlining of inlined interfaces
  • JDK-8268512: More content for ContentInfo
  • JDK-8268795: Enhance digests of Jar files
  • JDK-8268801: Improve PKCS attribute handling
  • JDK-8268813, CVE-2022-21283: Better String matching
  • JDK-8269151: Better construction of EncryptedPrivateKeyInfo
  • JDK-8269944: Better HTTP transport redux
  • JDK-8270386, CVE-2022-21291: Better verification of scan methods
  • JDK-8270392, CVE-2022-21293: Improve String constructions
  • JDK-8270416, CVE-2022-21294: Enhance construction of Identity maps
  • JDK-8270492, CVE-2022-21282: Better resolution of URIs
  • JDK-8270498, CVE-2022-21296: Improve SAX Parser configuration management
  • JDK-8270646, CVE-2022-21299: Improved scanning of XML entities
  • JDK-8270952, CVE-2022-21277: Improve TIFF file handling
  • JDK-8271962: Better TrueType font loading
  • JDK-8271968: Better canonical naming
  • JDK-8271987: Manifest improved manifest entries
  • JDK-8272014, CVE-2022-21305: Better array indexing
  • JDK-8272026, CVE-2022-21340: Verify Jar Verification
  • JDK-8272236, CVE-2022-21341: Improve serial forms for transport
  • JDK-8272272: Enhance jcmd communication
  • JDK-8272462: Enhance image handling
  • JDK-8273290: Enhance sound handling
  • JDK-8273756, CVE-2022-21360: Enhance BMP image support
  • JDK-8273838, CVE-2022-21365: Enhanced BMP processing
  • JDK-8274096, CVE-2022-21366: Improve decoding of image files
  • JDK-8279541: Improve HarfBuzz

Major Changes

  • JDK-8250554 : New Option Added to jcmd for Writing a gzipped Heap Dump
  • JDK-8260310: Configurable Extensions With System Properties
  • JDK-8272907: New SunPKCS11 Configuration Properties
  • JDK-8271517: Zip File System Provider Throws ZipException when entry name element contains "." or "."
  • JDK-8272535: Removed Google's GlobalSign Root Certificate
  • JDK-8274857: Update Timezone Data to 2021c
  • JDK-8253866: blacklisted.certs renamed to blocked.certs

FIPS Mode Changes

  • Fix FIPS issues in native code and with initialisation of java.security.Security

This update has been submitted for testing by ahughes.

4 months ago

This update's test gating status has been changed to 'ignored'.

4 months ago

ahughes edited this update.

4 months ago
User Icon browseria commented & provided feedback 4 months ago
karma

Works for me!

FEDORA-2022-6f70fc511d ejected from the push because "Cannot find relevant tag for java-11-openjdk-11.0.14.0.9-2.fc34. None of ['f34-updates-testing', 'f34-updates-testing-pending'] are in ['epel9-next-testing-candidate', 'epel7-testing-candidate', 'dist-5E-epel-testing-candidate', 'f27-modular-updates-candidate', 'f34-container-updates-candidate', 'eln-updates-candidate', 'f30-modular-updates-candidate', 'f28-modular-updates-candidate', 'f28-container-updates-candidate', 'f30-container-updates-candidate', 'epel8-testing-candidate', 'f30-flatpak-updates-candidate', 'f35-container-updates-candidate', 'f32-modular-updates-candidate', 'f29-modular-updates-candidate', 'f29-container-updates-candidate', 'f29-flatpak-updates-candidate', 'f22-updates-candidate', 'f21-updates-candidate', 'f25-updates-candidate', 'f24-updates-candidate', 'f23-updates-candidate', 'f26-updates-candidate', 'f31-modular-updates-candidate', 'dist-6E-epel-testing-candidate', 'f32-flatpak-updates-candidate', 'f35-flatpak-updates-candidate', 'f27-updates-candidate', 'f28-updates-candidate', 'f30-updates-candidate', 'f29-updates-candidate', 'el8-modular-updates-candidate', 'f32-updates-candidate', 'epel9-testing-candidate', 'f31-updates-candidate', 'f31-container-updates-candidate', 'f31-flatpak-updates-candidate', 'f34-updates-candidate', 'f34-modular-updates-candidate', 'f34-flatpak-updates-candidate', 'f36-container-updates-candidate', 'f32-container-updates-candidate', 'epel8-next-testing-candidate', 'f35-updates-candidate', 'f35-modular-updates-candidate', 'f33-updates-candidate', 'f36-updates-candidate', 'f33-modular-updates-candidate', 'f33-container-updates-candidate', 'f33-flatpak-updates-candidate']."

4 months ago

This update has been submitted for testing by kevin.

3 months ago

This update has been pushed to testing.

3 months ago

This update has been obsoleted by java-11-openjdk-11.0.14.1.1-1.fc34.

3 months ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
1
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
4 months ago
in testing
3 months ago
modified
4 months ago

Automated Test Results