java-1.8.0-openjdk-1.8.0.502.b07-1.1.el8

エラータID: AXSA:2026-1388:12

Release date: 
Thursday, July 30, 2026 - 12:55
Subject: 
java-1.8.0-openjdk-1.8.0.502.b07-1.1.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment
and the OpenJDK 8 Java Software Development Kit.

Security Fix(es):

JDK: Enhance TLS certificate handling (CVE-2026-46968)
JDK: Enhance JPEG handling (CVE-2026-47010)
JDK: Enhance XBM image support (CVE-2026-47021)
JDK: Enhance Jar file processing (CVE-2026-47027)
JDK: Improve certification checking (CVE-2026-60147)
JDK: Enhance AWT ImagingLib (CVE-2026-47059)
JDK: Enhance Jar handling (CVE-2026-47063)
JDK: Improve Nashorn index handling (CVE-2026-47057)
JDK: Enhance Dataview Implementation (CVE-2026-47058)
JDK: Update LCMS to 2.19 (CVE-2026-41254)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

CVE(s):
CVE-2026-46968
Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
CVE-2026-47010
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
CVE-2026-47021
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
CVE-2026-47027
Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
CVE-2026-60147
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
CVE-2026-47059
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
CVE-2026-47063
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
CVE-2026-47057
Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-47058
Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
CVE-2026-41254
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. java-1.8.0-openjdk-1.8.0.502.b07-1.1.el8.src.rpm
    MD5: 5f97f4d6562ddca4bb828a600cfffb60
    SHA-256: a5516bb4ff6a6d12c7f6bc9a8bfdd2f9388fbf29b685d0cbaad4b8a025477ac8
    Size: 58.66 MB

Asianux Server 8 for x86_64
  1. java-1.8.0-openjdk-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: b31f742341478d1476fcbeedcbf73839
    SHA-256: ad352377b73b5eafa7a026921da94a0aedc7cdb4cc70ad7c8207b755a9445f14
    Size: 564.09 kB
  2. java-1.8.0-openjdk-accessibility-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: cabc85d681350ccf63419a7713568863
    SHA-256: ac058f84b8b7e1b3f2bfa445737e2eaaecc3acb1f796c8dcd156d9138c4a941d
    Size: 134.51 kB
  3. java-1.8.0-openjdk-accessibility-fastdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: 836f8fe751042707cd4fcce102919056
    SHA-256: 4d5dea7dcf5b2b00f76171f4cdfd16964e593606fd83247ed5ae841787a4bd2c
    Size: 134.35 kB
  4. java-1.8.0-openjdk-accessibility-slowdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: a853e64f6f30c8bd03a544678dc86921
    SHA-256: 673e3e473d28b3312b086c93c54e2a51c42a14cfc29d51330aee507e404d4949
    Size: 134.36 kB
  5. java-1.8.0-openjdk-demo-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: cd337c5b1a3d3ba4ff63b9d0ea3d0758
    SHA-256: a75b845213163559613d4f79716538439a412b227588b7e757542a0d29661d9c
    Size: 2.09 MB
  6. java-1.8.0-openjdk-demo-fastdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: 8f6d4739596a337ef8c30dcf4e6adc98
    SHA-256: e2bdc53ddb5b70ac0a0a2fb99014c6b4030425486a97d9fbd75638cfd4cc823b
    Size: 2.12 MB
  7. java-1.8.0-openjdk-demo-slowdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: 60709b5a86f8b2307ca747d7d51d8528
    SHA-256: 80817fb84504b6800053a209910dd50d0f61b9d0f73bfd233f6e313100523cd7
    Size: 2.12 MB
  8. java-1.8.0-openjdk-devel-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: 5695dade6ad9582f67495fddfd415a67
    SHA-256: 0d6c4e0d73ed9ce9c79e0bc20d6d56043ab234d10968741b9a6ea4f16844e204
    Size: 9.97 MB
  9. java-1.8.0-openjdk-devel-fastdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: c41d10d5fbe2f073c2f48999c7f5498d
    SHA-256: cec1abac587873fa532760aa968e4274a1789c72ae8d30d64354c70776652cd1
    Size: 9.98 MB
  10. java-1.8.0-openjdk-devel-slowdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: f2c8e8f14f4d31cfed703d09b97b3fea
    SHA-256: bbae0df4a0f28cd3960c3641366f3f315d555f8ebda76b304a4a957140ab126e
    Size: 9.98 MB
  11. java-1.8.0-openjdk-fastdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: 9b48b1df39c05b83f85e3802a6f87d53
    SHA-256: dbd9f2de99bc3b6a33a816dcfa16de34c08ab0047f1c710b4486b6286adda13b
    Size: 577.19 kB
  12. java-1.8.0-openjdk-headless-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: 2afaca1fe8f55cdf6293b556d3d33348
    SHA-256: f44e792a1a6046523078f35e89914b9618a5e51498f4f11793c46c2761b600dd
    Size: 34.94 MB
  13. java-1.8.0-openjdk-headless-fastdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: 8626db9a657a19d78b3972fb0ac5195f
    SHA-256: 7c76eb023e37c708df762f416780af94cf9ac9370b9d57bae38808c7ac04ea89
    Size: 38.59 MB
  14. java-1.8.0-openjdk-headless-slowdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: d90273e82851fa6a143c0bf9bf93cb9a
    SHA-256: feecee0e0b42d6e712e1bf4196137f062fed3a1b2fc37a09ffed474c25a62fc9
    Size: 36.78 MB
  15. java-1.8.0-openjdk-javadoc-1.8.0.502.b07-1.1.el8.noarch.rpm
    MD5: 537f05f3e3cb5dfda092377b853a2847
    SHA-256: 34932c2001816fab97b57f151d6faa9a8ce5060cc06a264f85474f1231120712
    Size: 15.21 MB
  16. java-1.8.0-openjdk-javadoc-zip-1.8.0.502.b07-1.1.el8.noarch.rpm
    MD5: e77bfa59f5ed6fe7189768bb10dc9d56
    SHA-256: 17a31390981c34a5bc4497d0774bcebd446a9fa3aa26a530a71f8cbb5d123295
    Size: 41.73 MB
  17. java-1.8.0-openjdk-slowdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: 53fa9cf86acf6bdfb94a12bf134e7743
    SHA-256: a711efe172aadb72744fd578961bd89717434cdf144007076719990a3c275cbd
    Size: 553.64 kB
  18. java-1.8.0-openjdk-src-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: ea3b38afa44a5ed5c2faea48d5e4886e
    SHA-256: d2cba6eeec66c47ac499f80ed8819d193790f04c1ac7d790d58374e237d2e155
    Size: 45.55 MB
  19. java-1.8.0-openjdk-src-fastdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: face61349f097ed4137d1b86dabe5e5c
    SHA-256: 90d983d3c7a5e830559901c4267c2c5f9a0acba9749c877691429c0d4003352f
    Size: 45.55 MB
  20. java-1.8.0-openjdk-src-slowdebug-1.8.0.502.b07-1.1.el8.x86_64.rpm
    MD5: 31cee41bd4a8db78181c4a573b1e06cb
    SHA-256: 249a884a692f99c03e3315b01a54cad1024ab745f1991a23cd1be6e347f29b2d
    Size: 45.55 MB