gpp_maybe Security update for java-1_8_0-ibm
SUSE-SLE-Module-Legacy-15-SP7-2025-3262


This update for java-1_8_0-ibm fixes the following issues: Update to Java 8.0 Service Refresh 8 Fix Pack 50. Security issues fixed: - Oracle July 15 2025 CPU (bsc#1247754). - CVE-2025-30749: heap corruption allows unauthenticated attacker with network access to compromise and takeover Java applications that load and run untrusted code (bsc#1246595). - CVE-2025-30754: incomplete handshake allows unauthenticated attacker with network access via TLS to gain unauthorized update, insert, delete and read access to sensitive data (bsc#1246598). - CVE-2025-30761: issue in the Scripting component allows unauthenticated attacker with network access to gain unauthorized creation, deletion or modification access to critical data (bsc#1246580). - CVE-2025-50059: issue in the Networking component allows unauthenticated attacker with network access to gain unauthorized access to critical data (bsc#1246575). - CVE-2025-50106: Glyph out-of-memory access allows unauthenticated attacker with network access to compromise and takeover Java applications that load and run untrusted code (bsc#1246584). Other issues fixed: - Class Libraries: - Oracle Security Fix 8348989: Better Glyph drawing. - Removal of Baltimore root certificate and TWO CAMERFIRMA root CA certificates from CACERTS. - Update timezone information to the latest TZDATA2025B. - Java Virtual Machine: - Assertion failure at copyforwardscheme.cpp. - JIT Compiler: - GC assert due to an invalid object reference. - SIGILL from JIT compiled method. - Unexpected behaviour with very large arrays. - Security: - Deserialization of a serialized RSAPrivateCrtKey is throwing an exception. - EDDSAsignature fails when doing multiple update. - HTTPS channel binding support. - IBMJCEPlus provider supports post quantum cryptography algorithms ML-KEM (key encapsulation) and ML-DSA (digital signature). - Key certificate management: Extended key usage cannot be set without having key usage extension in certificate request. - MessageDigest.update API does not throw the correct exception. - Oracle Security Fix 8349594: Enhance TLS protocol support. - Problem getting key in PKCS12 keystore on MAC. - TLS support for the EDDSA signature algorithm. - Wrong algorithm name returned for EDDSA keys. - z/OS Extentions: - IBMJCEHybridException with hybrid provider in GCM mode.


cloud_download Downloads

Legacy Module 15.7 ppc64le
  • Packages
    java-1_8_0-ibm
    IBM Java(TM) Version 8 Runtime Environment
    1.8.0_sr8.50-150000.3.104.1 lock rpm lock nosrc
    java-1_8_0-ibm-demo
    Demonstration files for java-1_8_0-ibm
    1.8.0_sr8.50-150000.3.104.1 lock rpm
    java-1_8_0-ibm-devel
    IBM Java(TM) Version 8 SDK, Standard Edition
    1.8.0_sr8.50-150000.3.104.1 lock rpm
    java-1_8_0-ibm-src
    IBM Java(TM) Version 8 sources
    1.8.0_sr8.50-150000.3.104.1 lock rpm
Legacy Module 15.7 s390x
  • Packages
    java-1_8_0-ibm
    IBM Java(TM) Version 8 Runtime Environment
    1.8.0_sr8.50-150000.3.104.1 lock rpm lock nosrc
    java-1_8_0-ibm-demo
    Demonstration files for java-1_8_0-ibm
    1.8.0_sr8.50-150000.3.104.1 lock rpm
    java-1_8_0-ibm-devel
    IBM Java(TM) Version 8 SDK, Standard Edition
    1.8.0_sr8.50-150000.3.104.1 lock rpm
    java-1_8_0-ibm-src
    IBM Java(TM) Version 8 sources
    1.8.0_sr8.50-150000.3.104.1 lock rpm
Legacy Module 15.7 x86_64
  • Packages
    java-1_8_0-ibm
    IBM Java(TM) Version 8 Runtime Environment
    1.8.0_sr8.50-150000.3.104.1 lock rpm lock nosrc
    java-1_8_0-ibm-alsa
    ALSA support for java-1_8_0-ibm
    1.8.0_sr8.50-150000.3.104.1 lock rpm
    java-1_8_0-ibm-demo
    Demonstration files for java-1_8_0-ibm
    1.8.0_sr8.50-150000.3.104.1 lock rpm
    java-1_8_0-ibm-devel
    IBM Java(TM) Version 8 SDK, Standard Edition
    1.8.0_sr8.50-150000.3.104.1 lock rpm
    java-1_8_0-ibm-plugin
    Browser plugin files for java-1_8_0-ibm
    1.8.0_sr8.50-150000.3.104.1 lock rpm
    java-1_8_0-ibm-src
    IBM Java(TM) Version 8 sources
    1.8.0_sr8.50-150000.3.104.1 lock rpm