Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2036-1

Опубликовано: 21 мая 2026
Источник: suse-cvrf

Описание

Security update for java-1_8_0-openj9

This update for java-1_8_0-openj9 fixes the following issues

  • CVE-2026-1188: eclipse: ensure room for separator in omrsysinfo_get_processor_feature_string (bsc#1265261).
  • CVE-2026-22007: APIs in the specified component can lead to an unauthorized read access (bsc#1262490).
  • CVE-2026-22013: unauthenticated attacker with network access can access to critical data (bsc#1262494).
  • CVE-2026-22016: APIs in the specified Component can cause unauthorized access to critical data (bsc#1262495).
  • CVE-2026-22018: unauthenticated attacker with network access can cause a partial denial of service (bsc#1262496).
  • CVE-2026-22021: APIs in the specified Component can cause a partial denial of service (bsc#1262497).
  • CVE-2026-23865: Integer overflow in the tt_var_load_item_variation_store function (bsc#1259118).
  • CVE-2026-34268: unauthenticated attacker with logon can gain unauthorized read access (bsc#1262500).

Changes for java-1_8_0-openj9:

  • Update to OpenJDK 8u492 build 09 with OpenJ9 0.59.0 virtual machine

Список пакетов

SUSE Linux Enterprise Module for Package Hub 15 SP7
java-1_8_0-openj9-1.8.0.492-150200.3.68.1
java-1_8_0-openj9-accessibility-1.8.0.492-150200.3.68.1
java-1_8_0-openj9-demo-1.8.0.492-150200.3.68.1
java-1_8_0-openj9-devel-1.8.0.492-150200.3.68.1
java-1_8_0-openj9-headless-1.8.0.492-150200.3.68.1
java-1_8_0-openj9-src-1.8.0.492-150200.3.68.1

Описание

In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was not accounting for the separator inserted between processor features. If the output buffer supplied to this function was incorrectly sized, failing to account for the separator when determining when a write to the buffer was safe could lead to a buffer overflow. This issue is fixed in Eclipse OMR version 0.8.0.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-accessibility-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-demo-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-devel-1.8.0.492-150200.3.68.1

Ссылки

Описание

unknown


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-accessibility-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-demo-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-devel-1.8.0.492-150200.3.68.1

Ссылки

Описание

unknown


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-accessibility-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-demo-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-devel-1.8.0.492-150200.3.68.1

Ссылки

Описание

unknown


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-accessibility-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-demo-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-devel-1.8.0.492-150200.3.68.1

Ссылки

Описание

unknown


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-accessibility-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-demo-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-devel-1.8.0.492-150200.3.68.1

Ссылки

Описание

unknown


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-accessibility-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-demo-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-devel-1.8.0.492-150200.3.68.1

Ссылки

Описание

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-accessibility-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-demo-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-devel-1.8.0.492-150200.3.68.1

Ссылки

Описание

unknown


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-accessibility-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-demo-1.8.0.492-150200.3.68.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:java-1_8_0-openj9-devel-1.8.0.492-150200.3.68.1

Ссылки