|
|
Log in / Subscribe / Register

Ubuntu alert USN-7901-1 (openjdk-21-crac)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7901-1] CRaC JDK 21 vulnerabilities
Date:  Tue, 02 Dec 2025 01:57:26 +0000
Message-ID:  <E1vQFdu-00051U-Ba@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-7901-1 December 01, 2025 openjdk-21-crac vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 25.04 Summary: Several security issues were fixed in CRaC JDK 21. Software Description: - openjdk-21-crac: Open Source Java implementation with Coordinated Restore at Checkpoints Details: Jinfeng Guo discovered that the Security component of CRaC JDK 21 did not correctly handle certain representations of encoded strings. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. (CVE-2025-53057) Darius Bohni discovered that the JAXP component of CRaC JDK 21 was vulnerable to a XML External Entity (XEE) attack. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. (CVE-2025-53066) Yakov Shafranovich discovered that the Libraries component of CRaC JDK 21 contained an issue where certain Strings built with StringBuilder returned an incorrect result for String.equals() checks. An unauthenticated remote attacker could possibly use this issue to update, insert, or delete accessible data. (CVE-2025-61748) In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://openjdk.org/groups/vulnerability/advisories/2025-... Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 openjdk-21-crac-jdk 21.0.9+10-0ubuntu1~25.10 openjdk-21-crac-jdk-headless 21.0.9+10-0ubuntu1~25.10 openjdk-21-crac-jre 21.0.9+10-0ubuntu1~25.10 openjdk-21-crac-jre-headless 21.0.9+10-0ubuntu1~25.10 openjdk-21-crac-jre-zero 21.0.9+10-0ubuntu1~25.10 Ubuntu 25.04 openjdk-21-crac-jdk 21.0.9+10-0ubuntu1~25.04 openjdk-21-crac-jdk-headless 21.0.9+10-0ubuntu1~25.04 openjdk-21-crac-jre 21.0.9+10-0ubuntu1~25.04 openjdk-21-crac-jre-headless 21.0.9+10-0ubuntu1~25.04 openjdk-21-crac-jre-zero 21.0.9+10-0ubuntu1~25.04 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart Java applications to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7901-1 CVE-2025-53057, CVE-2025-53066, CVE-2025-61748 Package Information: https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0... https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmkuRlcACgkQcpJm3tlz hgFEsQ/+NVnTUgXsLBBxlxK25jToghCHTsaa4V+IMm88xAuqVHsLVSoQpC6U4f96 76KNTtxkl6Tx1bDMSaT6ujQojzY8Ym2gQiXiCU8wIR5K4RdHQoQuitQjHVFggL+5 hj+t7cXhAwF9pdzUqqFxDbW5fEC/V6fBqJuFykyCsZD/2TYtT0CVpyK44UDMDqrQ QYhJ+oSCqdjWzoGWosHgiqFuUkeaYJeT7XEfo+b+4LzGgdFZ6Q1XqopFytroMZRe vyVNc8qaGco3Edric275W0TUHAU9qj+kJeXo+6OY5t0Uzl89lAXD5c0upVn8S2XI 8ToXSHRhvCucoWhvcNome1Tv1otMNU1RygO5FjTSmO/YA0Qg+JE/HPZT29jjR1rQ /gKubKBVAqpcLqOJky9KRXwmTCgaBQDaGpDdL6oMLezLpEIn68HbrmUwuWm5UOzt rar0rC++toKQJcCrTznq1BGjatBJhHJ8QWGXRmK1cBDWu9uYglg0hV8vv1n3hVxe l7BeupIp7Rz4K6sD9cjMAbxl/yWwtgGPv9bX7FxGe+5pk721rVMggFNmqT63GOl4 jL0GYeb1mi0Ht/26f+rJDR4mvAR9f8PwPCi8dmLilejzxAmItKCLmcpi1FfoBUhP XQve8nWRhklf/QntCZPoPNLrluV7KbRzqilptF1jlK/s09eubvI= =UkM6 -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds