RedHat has issued an advisory on April 14: https://rhn.redhat.com/errata/RHSA-2015-0809.html This corresponds to the latest Oracle Critical Patch Update: http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html Updated checked into Cauldron SVN. Freeze push requested. Reproducible: Steps to Reproduce:
Blocks: (none) => 14674Whiteboard: (none) => MGA5TOO
Fixed in java-1.8.0-openjdk-1.8.0.45-6.b13.1.mga5.
Status: NEW => RESOLVEDBlocks: 14674 => (none)Resolution: (none) => FIXEDWhiteboard: MGA5TOO => (none)
URL: (none) => http://lwn.net/Vulnerabilities/640410/
LWN reference for one CVE only affecting java8: http://lwn.net/Vulnerabilities/640607/