{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20943-1","published":"2026-06-11T07:34:54Z","modified":"2026-06-13T18:24:19.600416001Z","related":["CVE-2024-21208","CVE-2024-21210","CVE-2024-21217","CVE-2024-21235","CVE-2025-21502","CVE-2025-21587","CVE-2025-30691","CVE-2025-30698","CVE-2025-30749","CVE-2025-30754","CVE-2025-50059","CVE-2025-50106","CVE-2025-53057","CVE-2025-53066","CVE-2026-1188","CVE-2026-21925","CVE-2026-21932","CVE-2026-21933","CVE-2026-21945","CVE-2026-22007","CVE-2026-22013","CVE-2026-22016","CVE-2026-22018","CVE-2026-22021","CVE-2026-23865","CVE-2026-34268","CVE-2026-34282"],"upstream":["CVE-2024-21208","CVE-2024-21210","CVE-2024-21217","CVE-2024-21235","CVE-2025-21502","CVE-2025-21587","CVE-2025-30691","CVE-2025-30698","CVE-2025-30749","CVE-2025-30754","CVE-2025-50059","CVE-2025-50106","CVE-2025-53057","CVE-2025-53066","CVE-2026-1188","CVE-2026-21925","CVE-2026-21932","CVE-2026-21933","CVE-2026-21945","CVE-2026-22007","CVE-2026-22013","CVE-2026-22016","CVE-2026-22018","CVE-2026-22021","CVE-2026-23865","CVE-2026-34268","CVE-2026-34282"],"summary":"Security update for java-17-openj9","details":"This update for java-17-openj9 fixes the following issues:\n\nChanges in java-17-openj9:\n\n- Make post scripts less noisy (bsc#1267355)\n\n- Use libalternatives instead of update-alternatives for\n  distributions where libalternatives is available\n\n- Update to OpenJDK 17.0.19 with OpenJ9 0.59.0 virtual machine\n- Including Oracle April 2026 CPU changes\n  * CVE-2026-22007 (bsc#1262490), CVE-2026-22013 (bsc#1262494),\n    CVE-2026-22016 (bsc#1262495), CVE-2026-22018 (bsc#1262496),\n    CVE-2026-22021 (bsc#1262497), CVE-2026-23865 (bsc#1259118),\n    CVE-2026-34268 (bsc#1262500), CVE-2026-34282 (bsc#1262501)\n- OpenJ9 specific security fix\n  * CVE-2026-1188 (bsc#1265261)\n  * OpenJ9 changes, see\n    https://www.eclipse.org/openj9/docs/version0.59/\n\n- Update to OpenJDK 17.0.18 with OpenJ9 0.57.0 virtual machine\n- Including Oracle January 2026 CPU changes\n  * CVE-2026-21925 (bsc#1257034), CVE-2026-21932 (bsc#1257036),\n    CVE-2026-21933 (bsc#1257037), CVE-2026-21945 (bsc#1257038)\n  * OpenJ9 changes, see\n    https://www.eclipse.org/openj9/docs/version0.57/\n\n- Do not depend on update-desktop-files (jsc#PED-14507)\n\n- Update to OpenJDK 17.0.17 with OpenJ9 0.56.0 virtual machine\n- Including Oracle October 2025 CPU changes\n  * CVE-2025-53057 (bsc#1252414), CVE-2025-53066 (bsc#1252417)\n  * OpenJ9 changes, see\n    https://www.eclipse.org/openj9/docs/version0.56/\n\n- Update to OpenJDK 17.0.16 with OpenJ9 0.53.0 virtual machine\n- Including Oracle July 2025 CPU changes\n  * CVE-2025-30749 (bsc#1246595), CVE-2025-30754 (bsc#1246598),\n    CVE-2025-50059 (bsc#1246575), CVE-2025-50106 (bsc#1246584)\n  * OpenJ9 changes, see\n    https://www.eclipse.org/openj9/docs/version0.53/\n- Enable bootcycle build\n\n- Do not embed rebuild counter (bsc#1246806)\n\n- Add -std=gnu99 to CFLAGS to fix gcc15 compile time error. Since\n  the C++ part is on -std=gnu++98, this is the closest.\n- Added patch:\n  * fix-build-with-gcc15.patch\n    + fix a typo in omr that is fatal with gcc15\n\n- Update to OpenJDK 17.0.15 with OpenJ9 0.51.0 virtual machine\n- Including Oracle April 2025 CPU changes\n  * CVE-2025-21587 (bsc#1241274), CVE-2025-30691 (bsc#1241275),\n    CVE-2025-30698 (bsc#1241276)\n  * OpenJ9 changes, see\n    https://www.eclipse.org/openj9/docs/version0.51/\n\n- fix wrong execstack flag in libj9jit (bsc#1235844)\n\n- Update to OpenJDK 17.0.14 with OpenJ9 0.49.0 virtual machine\n- Including Oracle October 2024 and January 2025 CPU changes\n  * CVE-2024-21208 (bsc#1231702), CVE-2024-21210 (bsc#1231711),\n    CVE-2024-21217 (bsc#1231716), CVE-2024-21235 (bsc#1231719),\n    CVE-2025-21502 (bsc#1236278)\n  * OpenJ9 changes, see\n    https://www.eclipse.org/openj9/docs/version0.49/\n","affected":[{"package":{"name":"java-17-openj9","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/java-17-openj9&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.0.19.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"java-17-openj9":"17.0.19.0-bp160.1.1","java-17-openj9-demo":"17.0.19.0-bp160.1.1","java-17-openj9-devel":"17.0.19.0-bp160.1.1","java-17-openj9-headless":"17.0.19.0-bp160.1.1","java-17-openj9-javadoc":"17.0.19.0-bp160.1.1","java-17-openj9-jmods":"17.0.19.0-bp160.1.1","java-17-openj9-src":"17.0.19.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20943-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231702"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231711"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231716"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231719"},{"type":"REPORT","url":"https://bugzilla.suse.com/1235844"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236278"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236804"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241274"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241275"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241276"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246575"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246584"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246595"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246598"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246806"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252414"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252417"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257034"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257036"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257037"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257038"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259118"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262490"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262494"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262495"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262496"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262497"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262500"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262501"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265261"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267355"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-21208"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-21210"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-21217"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-21235"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-21502"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-21587"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-30691"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-30698"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-30749"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-30754"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-50059"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-50106"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-53057"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-53066"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1188"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21925"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21932"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21933"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21945"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22007"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22013"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22016"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22018"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22021"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23865"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34268"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34282"}]}