Описание
Security update for java-1_8_0-openj9
This update for java-1_8_0-openj9 fixes the following issues:
- CVE-2025-4447: Fixed buffer overflow in Eclipse OpenJ9 (bsc#1243429).
- CVE-2025-30698: Fixed 2D unauthorized data access and DoS (bsc#1241276).
- CVE-2025-30691: Fixed Compiler Unauthorized Data Access (bsc#1241275).
- CVE-2025-21587: Fixed unauthorized access, deletion or modification of critical data (bsc#1241274).
Other bugfixes:
- Fixed wrong execstack flag in libj9jit (bsc#1235844)
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP6
java-1_8_0-openj9-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-accessibility-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-demo-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-devel-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-headless-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-src-1.8.0.452-150200.3.54.2
SUSE Linux Enterprise Module for Package Hub 15 SP7
java-1_8_0-openj9-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-accessibility-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-demo-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-devel-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-headless-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-src-1.8.0.452-150200.3.54.2
openSUSE Leap 15.6
java-1_8_0-openj9-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-accessibility-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-demo-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-devel-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-headless-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-javadoc-1.8.0.452-150200.3.54.2
java-1_8_0-openj9-src-1.8.0.452-150200.3.54.2
Ссылки
- Link for SUSE-SU-2025:01954-1
- E-Mail link for SUSE-SU-2025:01954-1
- SUSE Security Ratings
- SUSE Bug 1235844
- SUSE Bug 1241274
- SUSE Bug 1241275
- SUSE Bug 1241276
- SUSE Bug 1243429
- SUSE CVE CVE-2025-21587 page
- SUSE CVE CVE-2025-30691 page
- SUSE CVE CVE-2025-30698 page
- SUSE CVE CVE-2025-4447 page
Описание
unknown
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-1.8.0.452-150200.3.54.2
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-accessibility-1.8.0.452-150200.3.54.2
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-demo-1.8.0.452-150200.3.54.2
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-devel-1.8.0.452-150200.3.54.2
Ссылки
- CVE-2025-21587
- SUSE Bug 1241274
Описание
unknown
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-1.8.0.452-150200.3.54.2
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-accessibility-1.8.0.452-150200.3.54.2
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-demo-1.8.0.452-150200.3.54.2
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-devel-1.8.0.452-150200.3.54.2
Ссылки
- CVE-2025-30691
- SUSE Bug 1241275
Описание
unknown
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-1.8.0.452-150200.3.54.2
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-accessibility-1.8.0.452-150200.3.54.2
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-demo-1.8.0.452-150200.3.54.2
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-devel-1.8.0.452-150200.3.54.2
Ссылки
- CVE-2025-30698
- SUSE Bug 1241274
- SUSE Bug 1241276
Описание
In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by modifying a file on disk that is read when the JVM starts.
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-1.8.0.452-150200.3.54.2
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-accessibility-1.8.0.452-150200.3.54.2
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-demo-1.8.0.452-150200.3.54.2
SUSE Linux Enterprise Module for Package Hub 15 SP6:java-1_8_0-openj9-devel-1.8.0.452-150200.3.54.2
Ссылки
- CVE-2025-4447
- SUSE Bug 1243429