java-1.8.0-openjdk-1.8.0.502.b07-1.1.el8
エラータID: AXSA:2026-1388:12
The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment
and the OpenJDK 8 Java Software Development Kit.
Security Fix(es):
JDK: Enhance TLS certificate handling (CVE-2026-46968)
JDK: Enhance JPEG handling (CVE-2026-47010)
JDK: Enhance XBM image support (CVE-2026-47021)
JDK: Enhance Jar file processing (CVE-2026-47027)
JDK: Improve certification checking (CVE-2026-60147)
JDK: Enhance AWT ImagingLib (CVE-2026-47059)
JDK: Enhance Jar handling (CVE-2026-47063)
JDK: Improve Nashorn index handling (CVE-2026-47057)
JDK: Enhance Dataview Implementation (CVE-2026-47058)
JDK: Update LCMS to 2.19 (CVE-2026-41254)
Enhancement(s):
For the last couple of years, OpenJDK has used a single build shared among
multiple RPMs and a tarball available on the customer portal. The single
"portable" build has a release number ('p') and each RPM has its own release
number ('r'). However, the RPM naming only showed the RPM release number, while
the version output from the build showed the portable release number, making it
unclear that they were different numbers. From this release onwards, a release
field of the form 'p.r' is always used for RPMs and the version output shows
'p'. (RHEL-212308, RHEL-212309, RHEL-212310, RHEL-212311, RHEL-212312,
RHEL-212313, RHEL-212314, RHEL-212315)
Bug Fix(es):
In previous releases, the RPM did not correctly own the subdirectories used
for documentation in /usr/share/doc and /usr/share/javadoc. This is fixed in
this release, so these subdirectories will be removed when the package is
uninstalled. (RHEL-212319, RHEL-212320, RHEL-212321, RHEL-212322, RHEL-212323,
RHEL-212324, RHEL-212325, RHEL-212326)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.
CVE(s):
CVE-2026-46968
CVE-2026-47010
CVE-2026-47021
CVE-2026-47027
CVE-2026-60147
CVE-2026-47059
CVE-2026-47063
CVE-2026-47057
CVE-2026-47058
CVE-2026-41254
Update packages.
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
N/A
SRPMS
- java-1.8.0-openjdk-1.8.0.502.b07-1.1.el8.src.rpm
MD5: 5f97f4d6562ddca4bb828a600cfffb60
SHA-256: a5516bb4ff6a6d12c7f6bc9a8bfdd2f9388fbf29b685d0cbaad4b8a025477ac8
Size: 58.66 MB
Asianux Server 8 for x86_64
- java-1.8.0-openjdk-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: b31f742341478d1476fcbeedcbf73839
SHA-256: ad352377b73b5eafa7a026921da94a0aedc7cdb4cc70ad7c8207b755a9445f14
Size: 564.09 kB - java-1.8.0-openjdk-accessibility-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: cabc85d681350ccf63419a7713568863
SHA-256: ac058f84b8b7e1b3f2bfa445737e2eaaecc3acb1f796c8dcd156d9138c4a941d
Size: 134.51 kB - java-1.8.0-openjdk-accessibility-fastdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: 836f8fe751042707cd4fcce102919056
SHA-256: 4d5dea7dcf5b2b00f76171f4cdfd16964e593606fd83247ed5ae841787a4bd2c
Size: 134.35 kB - java-1.8.0-openjdk-accessibility-slowdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: a853e64f6f30c8bd03a544678dc86921
SHA-256: 673e3e473d28b3312b086c93c54e2a51c42a14cfc29d51330aee507e404d4949
Size: 134.36 kB - java-1.8.0-openjdk-demo-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: cd337c5b1a3d3ba4ff63b9d0ea3d0758
SHA-256: a75b845213163559613d4f79716538439a412b227588b7e757542a0d29661d9c
Size: 2.09 MB - java-1.8.0-openjdk-demo-fastdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: 8f6d4739596a337ef8c30dcf4e6adc98
SHA-256: e2bdc53ddb5b70ac0a0a2fb99014c6b4030425486a97d9fbd75638cfd4cc823b
Size: 2.12 MB - java-1.8.0-openjdk-demo-slowdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: 60709b5a86f8b2307ca747d7d51d8528
SHA-256: 80817fb84504b6800053a209910dd50d0f61b9d0f73bfd233f6e313100523cd7
Size: 2.12 MB - java-1.8.0-openjdk-devel-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: 5695dade6ad9582f67495fddfd415a67
SHA-256: 0d6c4e0d73ed9ce9c79e0bc20d6d56043ab234d10968741b9a6ea4f16844e204
Size: 9.97 MB - java-1.8.0-openjdk-devel-fastdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: c41d10d5fbe2f073c2f48999c7f5498d
SHA-256: cec1abac587873fa532760aa968e4274a1789c72ae8d30d64354c70776652cd1
Size: 9.98 MB - java-1.8.0-openjdk-devel-slowdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: f2c8e8f14f4d31cfed703d09b97b3fea
SHA-256: bbae0df4a0f28cd3960c3641366f3f315d555f8ebda76b304a4a957140ab126e
Size: 9.98 MB - java-1.8.0-openjdk-fastdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: 9b48b1df39c05b83f85e3802a6f87d53
SHA-256: dbd9f2de99bc3b6a33a816dcfa16de34c08ab0047f1c710b4486b6286adda13b
Size: 577.19 kB - java-1.8.0-openjdk-headless-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: 2afaca1fe8f55cdf6293b556d3d33348
SHA-256: f44e792a1a6046523078f35e89914b9618a5e51498f4f11793c46c2761b600dd
Size: 34.94 MB - java-1.8.0-openjdk-headless-fastdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: 8626db9a657a19d78b3972fb0ac5195f
SHA-256: 7c76eb023e37c708df762f416780af94cf9ac9370b9d57bae38808c7ac04ea89
Size: 38.59 MB - java-1.8.0-openjdk-headless-slowdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: d90273e82851fa6a143c0bf9bf93cb9a
SHA-256: feecee0e0b42d6e712e1bf4196137f062fed3a1b2fc37a09ffed474c25a62fc9
Size: 36.78 MB - java-1.8.0-openjdk-javadoc-1.8.0.502.b07-1.1.el8.noarch.rpm
MD5: 537f05f3e3cb5dfda092377b853a2847
SHA-256: 34932c2001816fab97b57f151d6faa9a8ce5060cc06a264f85474f1231120712
Size: 15.21 MB - java-1.8.0-openjdk-javadoc-zip-1.8.0.502.b07-1.1.el8.noarch.rpm
MD5: e77bfa59f5ed6fe7189768bb10dc9d56
SHA-256: 17a31390981c34a5bc4497d0774bcebd446a9fa3aa26a530a71f8cbb5d123295
Size: 41.73 MB - java-1.8.0-openjdk-slowdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: 53fa9cf86acf6bdfb94a12bf134e7743
SHA-256: a711efe172aadb72744fd578961bd89717434cdf144007076719990a3c275cbd
Size: 553.64 kB - java-1.8.0-openjdk-src-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: ea3b38afa44a5ed5c2faea48d5e4886e
SHA-256: d2cba6eeec66c47ac499f80ed8819d193790f04c1ac7d790d58374e237d2e155
Size: 45.55 MB - java-1.8.0-openjdk-src-fastdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: face61349f097ed4137d1b86dabe5e5c
SHA-256: 90d983d3c7a5e830559901c4267c2c5f9a0acba9749c877691429c0d4003352f
Size: 45.55 MB - java-1.8.0-openjdk-src-slowdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
MD5: 31cee41bd4a8db78181c4a573b1e06cb
SHA-256: 249a884a692f99c03e3315b01a54cad1024ab745f1991a23cd1be6e347f29b2d
Size: 45.55 MB