{"affected":[],"aliases":[],"details":"This update for java-11-openjdk to version 11.0.2+7 fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2019-2422: Better FileChannel transfer performance (bsc#1122293)\n- CVE-2019-2426: Improve web server connections\n- CVE-2018-11212: Improve JPEG processing (bsc#1122299)\n- Better route routing\n- Better interface enumeration\n- Better interface lists\n- Improve BigDecimal support\n- Improve robot support\n- Better icon support\n- Choose printer defaults\n- Proper allocation handling\n- Initial class initialization\n- More reliable p11 transactions\n- Improve NIO stability\n- Better loading of classloader classes\n- Strengthen Windows Access Bridge Support\n- Improved data set handling\n- Improved LSA authentication\n- Libsunmscapi improved interactions\n\nNon-security issues fix:\n\n- Do not resolve by default the added JavaEE modules (bsc#1120431)\n- ~2.5% regression on compression benchmark starting with 12-b11\n- java.net.http.HttpClient hangs on 204 reply without Content-length 0\n- Add additional TeliaSonera root certificate\n- Add more ld preloading related info to hs_error file on Linux\n- Add test to exercise server-side client hello processing\n- AES encrypt performance regression in jdk11b11\n- AIX: ProcessBuilder: Piping between created processes does not work.\n- AIX: Some class library files are missing the Classpath exception\n- AppCDS crashes for some uses with JRuby\n- Automate vtable/itable stub size calculation\n- BarrierSetC1::generate_referent_check() confuses register allocator\n- Better HTTP Redirection\n- Catastrophic size_t underflow in BitMap::*_large methods\n- Clip.isRunning() may return true after Clip.stop() was called\n- Compiler thread creation should be bounded by available space in memory and Code Cache\n- com.sun.net.httpserver.HttpServer returns Content-length header for 204 response code\n- Default mask register for avx512 instructions\n- Delayed starting of debugging via jcmd\n- Disable all DES cipher suites\n- Disable anon and NULL cipher suites\n- Disable unsupported GCs for Zero\n- Epsilon alignment adjustments can overflow max TLAB size\n- Epsilon elastic TLAB sizing may cause misalignment\n- HotSpot update for vm_version.cpp to recognise updated VS2017\n- HttpClient does not retrieve files with large sizes over HTTP/1.1\n- IIOException 'tEXt chunk length is not proper' on opening png file\n- Improve TLS connection stability again\n- InitialDirContext ctor sometimes throws NPE if the server has sent a disconnection\n- Inspect stack during error reporting\n- Instead of circle rendered in appl window, but ellipse is produced JEditor Pane\n- Introduce diagnostic flag to abort VM on failed JIT compilation\n- Invalid assert(HeapBaseMinAddress > 0) in ReservedHeapSpace::initialize_compressed_heap\n- jar has issues with UNC-path arguments for the jar -C parameter [windows]\n- java.net.http HTTP client should allow specifying Origin and Referer headers\n- java.nio.file.Files.writeString writes garbled UTF-16 instead of UTF-8\n- JDK 11.0.1 l10n resource file update\n- JDWP Transport Listener: dt_socket thread crash\n- JVMTI ResourceExhausted should not be posted in CompilerThread\n- LDAPS communication failure with jdk 1.8.0_181\n- linux: Poor StrictMath performance due to non-optimized compilation\n- Missing synchronization when reading counters for live threads and peak thread count\n- NPE in SupportedGroupsExtension\n- OpenDataException thrown when constructing CompositeData for StackTraceElement\n- Parent class loader may not have a referred ClassLoaderData instance when obtained in Klass::class_in_module_of_loader\n- Populate handlers while holding streamHandlerLock\n- ppc64: Enable POWER9 CPU detection\n- print_location is not reliable enough (printing register info)\n- Reconsider default option for ClassPathURLCheck change done in JDK-8195874\n- Register to register spill may use AVX 512 move instruction on unsupported platform.\n- s390: Use of shift operators not covered by cpp standard\n- serviceability/sa/TestUniverse.java#id0 intermittently fails with assert(get_instanceKlass()->is_loaded()) failed: must be at least loaded\n- SIGBUS in CodeHeapState::print_names()\n- SIGSEGV in MethodArityHistogram() with -XX:+CountCompiledCalls\n- Soft reference reclamation race in com.sun.xml.internal.stream.util.ThreadLocalBufferAllocator\n- Swing apps are slow if displaying from a remote source to many local displays\n- switch jtreg to 4.2b13\n- Test library OSInfo.getSolarisVersion cannot determine Solaris version\n- TestOptionsWithRanges.java is very slow\n- TestOptionsWithRanges.java of '-XX:TLABSize=2147483648' fails intermittently\n- The Japanese message of FileNotFoundException garbled\n- The 'supported_groups' extension in ServerHellos\n- ThreadInfoCompositeData.toCompositeData fails to map ThreadInfo to CompositeData\n- TimeZone.getDisplayName given Locale.US doesn't always honor the Locale.\n- TLS 1.2 Support algorithm in SunPKCS11 provider\n- TLS 1.3 handshake server name indication is missing on a session resume\n- TLS 1.3 server fails if ClientHello doesn't have pre_shared_key and psk_key_exchange_modes\n- TLS 1.3 interop problems with OpenSSL 1.1.1 when used on the client side with mutual auth\n- tz: Upgrade time-zone data to tzdata2018g\n- Undefined behaviour in ADLC\n- Update avx512 implementation\n- URLStreamHandler initialization race\n- UseCompressedOops requirement check fails fails on 32-bit system\n- windows: Update OS detection code to recognize Windows Server 2019\n- x86: assert on unbound assembler Labels used as branch targets\n- x86: jck tests for ldc2_w bytecode fail\n- x86: sharedRuntimeTrig/sharedRuntimeTrans compiled without optimization\n- '-XX:OnOutOfMemoryError' uses fork instead of vfork\n","id":"SUSE-SU-2019:0221-1","modified":"2019-02-01T14:20:56Z","published":"2019-02-01T14:20:56Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20190221-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1120431"},{"type":"REPORT","url":"https://bugzilla.suse.com/1122293"},{"type":"REPORT","url":"https://bugzilla.suse.com/1122299"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-11212"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2422"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2426"}],"related":["CVE-2018-11212","CVE-2019-2422","CVE-2019-2426"],"summary":"Security update for java-11-openjdk","upstream":["CVE-2018-11212","CVE-2019-2422","CVE-2019-2426"]}