[jdk13u-dev] RFR: 8285591: [11] add signum checks in DSA.java engineVerify

Andrew John Hughes andrew at openjdk.java.net
Thu Jun 2 15:17:49 UTC 2022


On Mon, 30 May 2022 16:28:03 GMT, Andrew John Hughes <andrew at openjdk.org> wrote:

> This change was part of a security fix, JDK-8277233, for 17u during the April update. The rest of 8277233 did not apply to older releases, as it concerned code added to src/jdk.crypto.ec/share/classes/sun/security/ec/ECDSAOperations.java by JDK-8237218 in 15u.
> 
> However, the additional checks in src/java.base/share/classes/sun/security/provider/DSA.java that were included in the patch are applicable to older releases.

I see `jdk13u-fix-yes`

-------------

PR: https://git.openjdk.java.net/jdk13u-dev/pull/353


More information about the jdk-updates-dev mailing list