|
|
Log in / Subscribe / Register

Ubuntu alert USN-8341-1 (openjdk-26)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8341-1] OpenJDK 26 vulnerabilities
Date:  Thu, 28 May 2026 21:17:53 +0000
Message-ID:  <E1wSi6z-0004OA-Kd@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-8341-1 May 28, 2026 openjdk-26 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 Summary: Several security issues were fixed in OpenJDK 26. Software Description: - openjdk-26: Open Source Java implementation Details: Thomas Beckers discovered that the JAXP component of OpenJDK 26 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to gain unauthorized access to sensitive information. (CVE-2026-22016) It was discovered that the Networking component of OpenJDK 26 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2026-34282) It was discovered that the JSSE component of OpenJDK 26 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2026-22021) It was discovered that the JGSS component of OpenJDK 26 did not correctly authenticate certain APIs. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-22013) It was discovered that the 2D component of OpenJDK 26 did not correctly handle certain integer arithmetic. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to obtain sensitive information. (CVE-2026-23865) It was discovered that the Libraries component of OpenJDK 26 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to modify data. (CVE-2026-22008) It was discovered that the Libraries component of OpenJDK 26 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2026-22018) Ken Pyle discovered that the Security component of OpenJDK 26 did not correctly authenticate certain APIs. A local attacker could possibly use this issue to obtain sensitive information. (CVE-2026-22007, CVE-2026-34268) In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://openjdk.org/groups/vulnerability/advisories/2026-... Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS openjdk-26-jdk 26.0.1+8-2~26.04.2 openjdk-26-jdk-headless 26.0.1+8-2~26.04.2 openjdk-26-jre 26.0.1+8-2~26.04.2 openjdk-26-jre-headless 26.0.1+8-2~26.04.2 openjdk-26-jre-zero 26.0.1+8-2~26.04.2 Ubuntu 25.10 openjdk-26-jdk 26.0.1+8-2~25.10.2 openjdk-26-jdk-headless 26.0.1+8-2~25.10.2 openjdk-26-jre 26.0.1+8-2~25.10.2 openjdk-26-jre-headless 26.0.1+8-2~25.10.2 openjdk-26-jre-zero 26.0.1+8-2~25.10.2 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart any running Java applications to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8341-1 CVE-2026-22007, CVE-2026-22008, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-23865, CVE-2026-34268, CVE-2026-34282 Package Information: https://launchpad.net/ubuntu/+source/openjdk-26/26.0.1+8-... https://launchpad.net/ubuntu/+source/openjdk-26/26.0.1+8-...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoYpsAACgkQcpJm3tlz hgH4Gw//am7nCcrhBZsb0Duif9FsbGeK5rR49M09tXrZ0k9qqfr9CvkUXz3qrAU0 y8f5H2w/BW0wJMWmxH6hpOaKNYO/2GSMl64NNmgjTdpZq1GLaImtJ3ubToJ0C+Xj aXo6tiaJn0drvmzXHMSaTOTHzAMtv800Fr41bvxYIDRC7cl1KqZhqx7uyyDlTOHe SFA6TE4VHBT3oNy6xOPS/80fXq6I76VBi30c4bkGqwfStCUqb7BTMeg0DlVBSh2L uR/e05t6S008VpU0xGm/5uZ/lAlxSTfN24z9LdQk2O4lDSGALggUo5FQEMdrle5t 2cthoHqPWZkaoqQXLaP7WfqhaUw3udk/UDITxhB2llnGSZDZNeR5gti4/2km2wgy s0xKHWA8eDaRE7fKJCaczTBY7d38un2YOMzn5/E4UUl3AScdWfqLpn9rY5O++4aZ Z9F5s/Ya0g5Q2LEMQK3dfPmw4uRqCLNFerI8QGCFcDvicyKgBXHJr/LvctxBk2XH 8CDgCp/TZfCcr7J1ryx7DzxVkI5LmqI4CZJc6B5yNkWnX2vaNQ06h162U3qhlycr QXB0/eNt6tYLg1ANaQiPWE6EDiTi3EibPPflDoIdln89CstNE+LseuoTqBjaWY4F RdHcZXbzGurSJjqjVzh9AubSjcUzL/femvdl2xiU883emrluQW8= =mAt/ -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds