|
|
Log in / Subscribe / Register

Ubuntu alert USN-8689-1 (openjdk-26)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8689-1] OpenJDK 26 vulnerabilities
Date:  Mon, 31 Aug 2026 05:55:17 +0000
Message-ID:  <E1x0uzF-0004ac-NI@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8689-1 August 31, 2026 openjdk-26 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS Summary: Several security issues were fixed in OpenJDK 26. Software Description: - openjdk-26: Open Source Java implementation Details: It was discovered that the JSSE component of OpenJDK 26 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of OpenJDK 26 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-46917) It was discovered that the ImageIO component of OpenJDK 26 did not correctly authorize users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-47010) It was discovered that the 2D component of OpenJDK 26 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-47021, CVE-2026-47059) It was discovered that the Libraries component of OpenJDK 26 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-47027) It was discovered that the Security component of OpenJDK 26 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-60147) It was discovered that the Libraries component of OpenJDK 26 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-47063) Lian Owen discovered that the 2D (Little CMS) component of OpenJDK 26 did not correctly handle certain integer arithmetic. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-41254) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS openjdk-26-jdk 26.0.2+10-2~26.04.2 openjdk-26-jdk-headless 26.0.2+10-2~26.04.2 openjdk-26-jre 26.0.2+10-2~26.04.2 openjdk-26-jre-headless 26.0.2+10-2~26.04.2 openjdk-26-jre-zero 26.0.2+10-2~26.04.2 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart any running Java applications to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8689-1 CVE-2026-41254, CVE-2026-46917, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47059, CVE-2026-47063, CVE-2026-60147 Package Information: https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmqVFqEACgkQcpJm3tlz hgFOFg/+OYlWgQH6yuEblO7WxCCFYDxtQamif2ED/zgeMpsuj6/qecK8PzOYn+U8 EAMzpyFPdb1xD++f6S/vjmq/Ibk5fFUXNPx58lLLF4i3wZ6KKBjuqNmO/lq+IMMJ v3XoMbyk713V75xNQtxBXGe6AQg3u/KxtZzX2xYvmuGd6m9jcB0hBirfZeba6nkc cQkqGOTOZr/IeHy0MNnembCBqNZbaLbWn9dqMi3wy+wZVfkuwTZo8KoQzeG8ixQw Ke9M2yGhVRC9XaqyjPdx//vF+S9vvB4hovjRvTUkuYyQncaJRFAOAQjLNZAZcFQa ggknSWr7Lb+pf3ULiDXmrHuTX9JMc0M6uSsvuncjah6IruRv8XqXk1VjWNQ8Url8 Cwu+jvOViX3gYhMFwY4jdX7UEbl8vjrNLO+zJRke+vbT5PabEJyhPgRjzhz+I1vn J5YGpbrWhVZPY7gZfA439MVmkoZoUJ+Q2v3SXARuT6wLIXUkQVUuz4ZoFTOP3A9x a/cMHR7BBTr+wOqOyNhmny9ax5jhfOsUJv33KhFqqw6u5UkuJx9HGNVScUImb3mR RK8Y3QudSAsdIs3Rfe82bp79tAg8C3fhi2DPP2L11LocLgeHEQOoLzG3BXaWIB1x 7SPSXqeE9Ybtnwgh+yd8+sctHW04YpjXtUqSIV3WrLIY7lvLD/s= =un5e -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds