{"schema_version":"1.7.5","id":"SUSE-SU-2026:21543-1","published":"2026-05-04T12:34:30Z","modified":"2026-05-12T18:26:57.570348Z","related":["CVE-2026-22007","CVE-2026-22008","CVE-2026-22013","CVE-2026-22016","CVE-2026-22018","CVE-2026-22021","CVE-2026-23865","CVE-2026-34268","CVE-2026-34282"],"upstream":["CVE-2026-22007","CVE-2026-22008","CVE-2026-22013","CVE-2026-22016","CVE-2026-22018","CVE-2026-22021","CVE-2026-23865","CVE-2026-34268","CVE-2026-34282"],"summary":"Security update for java-25-openjdk","details":"This update for java-25-openjdk fixes the following issues:\n\nUpdate to upstream tag jdk-25.0.3+9 (April 2026 CPU).\n\nSecurity issues fixed:\n\n- CVE-2026-22007: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain\n  unauthorized read access to a subset of accessible data (bsc#1262490).\n- CVE-2026-22008: Libraries: unauthenticated attacker with network access via multiple protocols can gain unauthorized\n  update, insert or delete access to data (bsc#1262493).\n- CVE-2026-22013: JGSS: unauthenticated attacker with network access via multiple protocols can gain unauthorized\n  access to critical data (bsc#1262494).\n- CVE-2026-22016: JAXP: unauthenticated attacker with network access via multiple protocols can gain unauthorized\n  to access critical data (bsc#1262495).\n- CVE-2026-22018: Libraries: unauthenticated attacker with network access via multiple protocols can cause a partial\n  denial of service (bsc#1262496).\n- CVE-2026-22021: JSSE: unauthenticated attacker with network access via HTTPS can cause a partial denial of service\n  (bsc#1262497).\n- CVE-2026-23865: freetype2: integer overflow in the `tt_var_load_item_variation_store` function allows for an\n  out-of-bounds read when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts(bsc#1259118).\n- CVE-2026-34268: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain\n  unauthorized read access to a subset of data (bsc#1262500).\n- CVE-2026-34282: Networking: unauthenticated attacker with network access via multiple protocols can cause a hang or\n  frequently repeatable crash (bsc#1262501).\n\nOther updates and bugfixes:\n\n- Provide the timezone-java and tzdata-java (jsc#PED-15898).\n- Migrate to the new logic of FIPS patch developed by RedHat in https://github.com/rh-openjdk/jdk/tree/fips-25u.\n- Add the sources of /nss-native-fips-key-import-export-adapter.\n  * This native library is an adapter for OpenJDK to use the NSS PKCS #11 software token (libsoftokn3.so) in FIPS mode.\n- Allow overriding of gcc name.\n- Don't make missing system crypto-policies fatal.\n- Add create-crypto-properties-files.bash that generates during the build the config files for different fips and\n  non-fips scenarios.\n- Add TestSecurityProperties.java to test the loading of system security properties where applicable.\n","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621543-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259118"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262490"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262493"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262494"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262495"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262496"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262497"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262500"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262501"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22007"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22008"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22013"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22016"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22018"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22021"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23865"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34268"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34282"}]}