|
|
Log in / Subscribe / Register

SUSE alert openSUSE-SU-2026:0208-1 (java-17-openj9)

From:  maintenance@opensuse.org
To:  security-announce@lists.opensuse.org
Subject:  openSUSE-SU-2026:0208-1: important: Security update for java-17-openj9
Date:  Mon, 15 Jun 2026 15:05:49 +0200
Message-ID:  <20260615130549.49663FCE7@maintenance.suse.de>
Archive-link:  Article

openSUSE Security Update: Security update for java-17-openj9 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0208-1 Rating: important References: #1252414 #1252417 #1257034 #1257036 #1257037 #1257038 #1259118 #1262490 #1262494 #1262495 #1262496 #1262497 #1262500 #1262501 #1265261 #1267355 PED-14507 Cross-References: CVE-2025-53057 CVE-2025-53066 CVE-2026-1188 CVE-2026-21925 CVE-2026-21932 CVE-2026-21933 CVE-2026-21945 CVE-2026-22007 CVE-2026-22013 CVE-2026-22016 CVE-2026-22018 CVE-2026-22021 CVE-2026-23865 CVE-2026-34268 CVE-2026-34282 CVSS scores: CVE-2025-53057 (SUSE): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2025-53066 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-1188 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2026-21925 (SUSE): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N CVE-2026-21932 (SUSE): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N CVE-2026-21933 (SUSE): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE-2026-21945 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2026-22007 (SUSE): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-22013 (SUSE): 6 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-22016 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-22018 (SUSE): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVE-2026-22021 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVE-2026-23865 (SUSE): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVE-2026-34268 (SUSE): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-34282 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that solves 15 vulnerabilities, contains one feature and has one errata is now available. Description: This update for java-17-openj9 fixes the following issues: - Make post scripts less noisy (boo#1267355) - Use libalternatives instead of update-alternatives for distributions where libalternatives is available - Update to OpenJDK 17.0.19 with OpenJ9 0.59.0 virtual machine - Including Oracle April 2026 CPU changes * CVE-2026-22007 (boo#1262490), CVE-2026-22013 (boo#1262494), CVE-2026-22016 (boo#1262495), CVE-2026-22018 (boo#1262496), CVE-2026-22021 (boo#1262497), CVE-2026-23865 (boo#1259118), CVE-2026-34268 (boo#1262500), CVE-2026-34282 (boo#1262501) - OpenJ9 specific security fix * CVE-2026-1188 (boo#1265261) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.59/ - Update to OpenJDK 17.0.18 with OpenJ9 0.57.0 virtual machine - Including Oracle January 2026 CPU changes * CVE-2026-21925 (boo#1257034), CVE-2026-21932 (boo#1257036), CVE-2026-21933 (boo#1257037), CVE-2026-21945 (boo#1257038) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.57/ - Do not depend on update-desktop-files (jsc#PED-14507) - Update to OpenJDK 17.0.17 with OpenJ9 0.56.0 virtual machine - Including Oracle October 2025 CPU changes * CVE-2025-53057 (boo#1252414), CVE-2025-53066 (boo#1252417) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.56/ Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-208=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 ppc64le s390x x86_64): java-17-openj9-17.0.19.0-bp157.2.6.1 java-17-openj9-demo-17.0.19.0-bp157.2.6.1 java-17-openj9-devel-17.0.19.0-bp157.2.6.1 java-17-openj9-headless-17.0.19.0-bp157.2.6.1 java-17-openj9-jmods-17.0.19.0-bp157.2.6.1 java-17-openj9-src-17.0.19.0-bp157.2.6.1 - openSUSE Backports SLE-15-SP7 (noarch): java-17-openj9-javadoc-17.0.19.0-bp157.2.6.1 References: https://www.suse.com/security/cve/CVE-2025-53057.html https://www.suse.com/security/cve/CVE-2025-53066.html https://www.suse.com/security/cve/CVE-2026-1188.html https://www.suse.com/security/cve/CVE-2026-21925.html https://www.suse.com/security/cve/CVE-2026-21932.html https://www.suse.com/security/cve/CVE-2026-21933.html https://www.suse.com/security/cve/CVE-2026-21945.html https://www.suse.com/security/cve/CVE-2026-22007.html https://www.suse.com/security/cve/CVE-2026-22013.html https://www.suse.com/security/cve/CVE-2026-22016.html https://www.suse.com/security/cve/CVE-2026-22018.html https://www.suse.com/security/cve/CVE-2026-22021.html https://www.suse.com/security/cve/CVE-2026-23865.html https://www.suse.com/security/cve/CVE-2026-34268.html https://www.suse.com/security/cve/CVE-2026-34282.html https://bugzilla.suse.com/1252414 https://bugzilla.suse.com/1252417 https://bugzilla.suse.com/1257034 https://bugzilla.suse.com/1257036 https://bugzilla.suse.com/1257037 https://bugzilla.suse.com/1257038 https://bugzilla.suse.com/1259118 https://bugzilla.suse.com/1262490 https://bugzilla.suse.com/1262494 https://bugzilla.suse.com/1262495 https://bugzilla.suse.com/1262496 https://bugzilla.suse.com/1262497 https://bugzilla.suse.com/1262500 https://bugzilla.suse.com/1262501 https://bugzilla.suse.com/1265261 https://bugzilla.suse.com/1267355


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds