Описание
Security update for java-1_8_0-ibm
This update for java-1_8_0-ibm fixes the following issues:
Update to Java 8.0 Service Refresh 8 Fix Pack 70 (bsc#1273223).
- CVE-2026-16243: inconsistent handling of zero length data in
arraycmpof the SIMD evaluator (bsc#1274275). - CVE-2026-16439: using
-Xtraceto trace method arguments can lead to buffer underflow (bsc#1272250). - CVE-2026-16441: method resolution default method precedence failure (bsc#1272248).
- CVE-2026-41254: lcms2: information disclosure or denial of service via integer overflow in
CubeSize(bsc#1272459). - CVE-2026-46968: unauthorized creation, deletion or modification access to critical data (bsc#1272224).
- CVE-2026-47010: unauthorized update, insert or delete access to data (bsc#1272225).
- CVE-2026-47021: partial denial of service via multiple network protocols (bsc#1272227).
- CVE-2026-47027: partial denial of service via multiple network protocols (bsc#1272228).
- CVE-2026-47057: hang or frequently repeatable crash via multiple network protocols (bsc#1272233).
- CVE-2026-47058: unauthorized creation, deletion or modification access to critical data (bsc#1272234).
- CVE-2026-47059: partial denial of service via multiple network protocols (bsc#1272235).
- CVE-2026-47063: unauthorized creation, deletion or modification access to critical data (bsc#1272236).
- CVE-2026-60147: unauthorized update, insert or delete access to data (bsc#1272237).
- CVE-2026-8400: malicious IIOP server can induce loading and instantation of arbitrary classes (bsc#1274276).
Список пакетов
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
SUSE Linux Enterprise Module for Legacy 15 SP7
SUSE Linux Enterprise Server 15 SP4-LTSS
SUSE Linux Enterprise Server 15 SP5-LTSS
SUSE Linux Enterprise Server 15 SP6-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP6
Ссылки
- Link for SUSE-SU-2026:3615-1
- E-Mail link for SUSE-SU-2026:3615-1
- SUSE Security Ratings
- SUSE Bug 1272224
- SUSE Bug 1272225
- SUSE Bug 1272227
- SUSE Bug 1272228
- SUSE Bug 1272233
- SUSE Bug 1272234
- SUSE Bug 1272235
- SUSE Bug 1272236
- SUSE Bug 1272237
- SUSE Bug 1272248
- SUSE Bug 1272250
- SUSE Bug 1272459
- SUSE Bug 1273223
- SUSE Bug 1274275
- SUSE Bug 1274276
- SUSE CVE CVE-2026-16243 page
- SUSE CVE CVE-2026-16439 page
Описание
In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero.
Затронутые продукты
Ссылки
- CVE-2026-16243
- SUSE Bug 1272458
- SUSE Bug 1274275
Описание
In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.
Затронутые продукты
Ссылки
- CVE-2026-16439
- SUSE Bug 1272250
Описание
In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface default method.
Затронутые продукты
Ссылки
- CVE-2026-16441
- SUSE Bug 1272248
Описание
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
Затронутые продукты
Ссылки
- CVE-2026-41254
- SUSE Bug 1264994
- SUSE Bug 1272458
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-46968
- SUSE Bug 1272224
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-47010
- SUSE Bug 1272225
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-47021
- SUSE Bug 1272227
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-47027
- SUSE Bug 1272228
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-47057
- SUSE Bug 1272233
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-47058
- SUSE Bug 1272234
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-47059
- SUSE Bug 1272235
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-47063
- SUSE Bug 1272236
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-60147
- SUSE Bug 1272237
Описание
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
Затронутые продукты
Ссылки
- CVE-2026-8400
- SUSE Bug 1272458
- SUSE Bug 1274276