Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-55787

Опубликовано: 20 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2026-55787: java-21-openjdk security update (MODERATE)

[1:21.0.12.1.1-1.1.0.1]

  • Add Oracle vendor bug URL [Orabug: 34340155]

[1:21.0.12.1.1-1.1]

  • Update to jdk-21.0.12.1+1 (GA)
  • Update release notes to 21.0.12.1+1
  • Sync the copy of the portable specfile with the latest update
  • ** This tarball is embargoed until 2026-08-18 @ 1pm PT. **
  • Resolves: RHEL-235610

[1:21.0.12.0.8-2.1]

  • Add CVEs to NEWS file
  • Update to tarball with final changeset ID
  • Sync the copy of the portable specfile with the latest update
  • Related: RHEL-188853

[1:21.0.12.0.8-1.1]

  • Update to jdk-21.0.12+8 (GA)
  • Update release notes to 21.0.12+8
  • Bump freetype version to 2.14.3 following JDK-8385390
  • Bump giflib version to 6.1.3 following JDK-8384902
  • Bump HarfBuzz version to 14.2.0 following JDK-8385490
  • Bump lcms2 version to 2.19.1 following JDK-8375065 & JDK-8383354
  • Bump libpng version to 1.6.58 following JDK-8384495
  • Update tagging scripts to include signature checks and correctly handle gating
  • Update tagged versions to include 9.8.0-z, 9.9.0, 10.2-z & 10.3.
  • Add gating scripts to simplify obtaining results and waiving issues
  • Cleanup tagging and gating scripts to appease shellcheck:
    • scripts/builds/build_vanilla.sh: Use an array to handle the varying arguments to rhpkg.
    • scripts/builds/check_signatures.sh: Quote variable usage.
    • scripts/builds/waive_issue.sh: Remove redundant 'test 'x'' usage.
    • scripts/builds/waive_leapp_issue.sh: Likewise.
    • scripts/builds/waive_rpminspect.sh: Likewise.
    • scripts/builds/waive_usual_rpminspect.sh: Likewise and add missing WORKING_DIR variable.
    • scripts/builds/waive_usual_tier0.sh: Remove redundant 'test 'x'' usage.
  • Remove macro references in comments where possible (%dnl not compatible enough yet)
  • Move version information and core NVR definitions back towards the top of the file
  • Specify portablerelease and rpmrelease (always 0 for portables) in the Release field
  • Obsolete old RHEL releases (9.7.0-z, 10.1-z)
  • Make zone string debug output optional in TestTranslations
  • Change javadoc-zip to just own the top-level directory, not include the entire subtree
  • Sync the copy of the portable specfile with the latest update
  • ** This tarball is embargoed until 2026-07-21 @ 1pm PT. **
  • Resolves: RHEL-212331
  • Resolves: RHEL-212333
  • Resolves: RHEL-212335
  • Resolves: RHEL-212351
  • Resolves: RHEL-212337
  • Resolves: RHEL-188853
  • Resolves: RHEL-212344
  • Resolves: RHEL-212346
  • Related: RHEL-212353

[1:21.0.11.0.10-1.2]

  • Disable abidiff inspection in rpminspect.yaml to avoid an out-of-memory error on the CentOS test farm
  • See: https://docs.testing-farm.io/Testing%20Farm/0.1/errors.html#TFE-1
  • Do not overwrite slowdebug __provides_exclude_from and __requires_exclude_from regexps
  • Make headless own /usr/share/doc/java-1.8.0-openjdk
  • Make javadoc-zip own /usr/share/javadoc/java-1.8.0-openjdk
  • Resolves: RHEL-212350
  • Resolves: RHEL-212352
  • Resolves: RHEL-212353

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

java-21-openjdk-demo-fastdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-demo-slowdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-devel-fastdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-devel-slowdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-fastdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-headless-fastdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-headless-slowdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-jmods-fastdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-jmods-slowdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-slowdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-src-fastdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-src-slowdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-static-libs-fastdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-static-libs-slowdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-demo

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-devel

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-headless

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-javadoc

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-javadoc-zip

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-jmods

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-src

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-static-libs

21.0.12.1.1-1.1.0.1.el8

Oracle Linux x86_64

java-21-openjdk-demo-fastdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-demo-slowdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-devel-fastdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-devel-slowdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-fastdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-headless-fastdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-headless-slowdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-jmods-fastdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-jmods-slowdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-slowdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-src-fastdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-src-slowdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-static-libs-fastdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-static-libs-slowdebug

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-demo

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-devel

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-headless

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-javadoc

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-javadoc-zip

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-jmods

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-src

21.0.12.1.1-1.1.0.1.el8

java-21-openjdk-static-libs

21.0.12.1.1-1.1.0.1.el8

Связанные уязвимости

rocky
3 дня назад

Moderate: java-21-openjdk security update

oracle-oval
3 дня назад

ELSA-2026-55781: java-17-openjdk security update (MODERATE)

oracle-oval
3 дня назад

ELSA-2026-55775: java-1.8.0-openjdk security update (MODERATE)

oracle-oval
3 дня назад

ELSA-2026-55798: java-25-openjdk security update (MODERATE)

CVSS3: 3.7
ubuntu
3 дня назад

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vec...