Описание
Security update for java-1_8_0-openj9
This update for java-1_8_0-openj9 fixes the following issues
- CVE-2026-1188: eclipse: ensure room for separator in omrsysinfo_get_processor_feature_string (bsc#1265261).
- CVE-2026-22007: APIs in the specified component can lead to an unauthorized read access (bsc#1262490).
- CVE-2026-22013: unauthenticated attacker with network access can access to critical data (bsc#1262494).
- CVE-2026-22016: APIs in the specified Component can cause unauthorized access to critical data (bsc#1262495).
- CVE-2026-22018: unauthenticated attacker with network access can cause a partial denial of service (bsc#1262496).
- CVE-2026-22021: APIs in the specified Component can cause a partial denial of service (bsc#1262497).
- CVE-2026-23865: Integer overflow in the tt_var_load_item_variation_store function (bsc#1259118).
- CVE-2026-34268: unauthenticated attacker with logon can gain unauthorized read access (bsc#1262500).
Changes for java-1_8_0-openj9:
- Update to OpenJDK 8u492 build 09 with OpenJ9 0.59.0 virtual machine
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP7
Ссылки
- Link for SUSE-SU-2026:2036-1
- E-Mail link for SUSE-SU-2026:2036-1
- SUSE Security Ratings
- SUSE Bug 1259118
- SUSE Bug 1262490
- SUSE Bug 1262494
- SUSE Bug 1262495
- SUSE Bug 1262496
- SUSE Bug 1262497
- SUSE Bug 1262500
- SUSE Bug 1265261
- SUSE CVE CVE-2026-1188 page
- SUSE CVE CVE-2026-22007 page
- SUSE CVE CVE-2026-22013 page
- SUSE CVE CVE-2026-22016 page
- SUSE CVE CVE-2026-22018 page
- SUSE CVE CVE-2026-22021 page
- SUSE CVE CVE-2026-23865 page
- SUSE CVE CVE-2026-34268 page
Описание
In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was not accounting for the separator inserted between processor features. If the output buffer supplied to this function was incorrectly sized, failing to account for the separator when determining when a write to the buffer was safe could lead to a buffer overflow. This issue is fixed in Eclipse OMR version 0.8.0.
Затронутые продукты
Ссылки
- CVE-2026-1188
- SUSE Bug 1265261
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-22007
- SUSE Bug 1262490
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-22013
- SUSE Bug 1262494
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-22016
- SUSE Bug 1262495
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-22018
- SUSE Bug 1262496
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-22021
- SUSE Bug 1262497
Описание
An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.
Затронутые продукты
Ссылки
- CVE-2026-23865
- SUSE Bug 1259118
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-34268
- SUSE Bug 1262500