java-21-openjdk-21.0.12.0.8-1.1.el8.ML.1
エラータID: AXSA:2026-1475:08
The OpenJDK 21 packages provide the OpenJDK 21 Java Runtime Environment and the
OpenJDK 21 Java Software Development Kit.
Security Fix(es):
JDK: Enhance TLS certificate handling (CVE-2026-46968)
JDK: Improve DTLS handshaking (CVE-2026-46917)
JDK: Enhance JPEG handling (CVE-2026-47010)
JDK: Enhance XBM image support (CVE-2026-47021)
JDK: Enhance Jar file processing (CVE-2026-47027)
JDK: Improve certification checking (CVE-2026-60147)
JDK: Enhance AWT ImagingLib (CVE-2026-47059)
JDK: Enhance Jar handling (CVE-2026-47063)
JDK: Update LCMS to 2.19 (CVE-2026-41254)
Enhancement(s):
For the last couple of years, OpenJDK has used a single build shared among
multiple RPMs and a tarball available on the customer portal. The single
"portable" build has a release number ('p') and each RPM has its own release
number ('r'). However, the RPM naming only showed the RPM release number, while
the version output from the build showed the portable release number, making it
unclear that they were different numbers. From this release onwards, a release
field of the form 'p.r' is always used for RPMs and the version output shows
'p'. (RHEL-212337, RHEL-212338, RHEL-212339, RHEL-212340, RHEL-212342,
RHEL-212343)
Bug Fix(es):
In previous releases, the RPM did not correctly own the subdirectories used
for documentation in /usr/share/doc and /usr/share/javadoc. This is fixed in
this release, so these subdirectories will be removed when the package is
uninstalled. (RHEL-212353, RHEL-212359, RHEL-212360, RHEL-212361)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.
CVE(s):
CVE-2026-46968
CVE-2026-46917
CVE-2026-47010
CVE-2026-47021
CVE-2026-47027
CVE-2026-60147
CVE-2026-47059
CVE-2026-47063
CVE-2026-41254
Update packages.
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
N/A
SRPMS
- java-21-openjdk-21.0.12.0.8-1.1.el8.ML.1.src.rpm
MD5: c1532b955ca764dea0f86fd9fad132d7
SHA-256: 567daaec867d088f032721c761be3ce2e96b8149fa2468dc457ebc29c189ba46
Size: 67.96 MB
Asianux Server 8 for x86_64
- java-21-openjdk-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: ac9e8194bfaa09ab89f0c2cb6419b74b
SHA-256: b3533ee0cc8b62699e9ef03218b94d562089acd70f62cc5d6c9cfe42236ab82e
Size: 428.79 kB - java-21-openjdk-demo-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: d62000d7aef9b7181b16d36aa084cff6
SHA-256: d552f95b9044bde366340a141e2793123ff7af4ea41603693ec0033e899aa7be
Size: 3.20 MB - java-21-openjdk-demo-fastdebug-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: a654fce64e75df83cde0b114fb715ff8
SHA-256: 6314c42cf222fc69138b19cfcd468e0296e6ab0a68c2c872581e30d666210942
Size: 3.20 MB - java-21-openjdk-demo-slowdebug-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: b4751955fe268c0b6998cf63ad05e1c7
SHA-256: dc50b1f8c84d741479021be6112f7b292af21e56544c71749d84b69077af6900
Size: 3.20 MB - java-21-openjdk-devel-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: 774142c4925b933601b92ae56b834ca6
SHA-256: 13d6862c982fe00a6a326e2c3da3b64910effaebf7da62092f0997f5a66210d3
Size: 5.17 MB - java-21-openjdk-devel-fastdebug-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: df4a6a95dd9dbbdb3ebbb6207bc4eebb
SHA-256: ecd95071225e20a23ea9e3b93db8b64a115189066bf08b5f0135673aa7c8cdb9
Size: 5.17 MB - java-21-openjdk-devel-slowdebug-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: 141ad90ad8c0e6a6fc73a71b0eb99552
SHA-256: 964cecc1c499c80a3b6c805ff896d3330970771fdf5d22a1135e4e6d92d9e5b4
Size: 5.17 MB - java-21-openjdk-fastdebug-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: 956917e31322ad1b09f10e1f048ed061
SHA-256: 8797ee03336c60430c313d611e2b1e5db77366049c4d272c110bb5bf2c0a7ce9
Size: 438.45 kB - java-21-openjdk-headless-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: 6ed82316a9358228826fa0dfa3a0fcda
SHA-256: 064ca5167a19062320ba677777042a36da6293d99a483794128ead9cab4f0261
Size: 49.57 MB - java-21-openjdk-headless-fastdebug-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: c1712da69ddd09b1fb56bfaa7132adfc
SHA-256: 0ca402f264fee030f6758ddce5eb0477a42b0d0cd8b296e5baa8bf478c9b3a57
Size: 54.35 MB - java-21-openjdk-headless-slowdebug-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: 54df502d0239f4b3e00d32472e77bed8
SHA-256: 1efa575b5d678632987daf409ccfeba4e56ab2b3a0cf138310c59e0799631b22
Size: 53.57 MB - java-21-openjdk-javadoc-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: cbfccb4b3190601087806d3d2342a799
SHA-256: 560905e2208131a1256df56134b41812fc94f2df2ea1c559e1dce7c01fdd093f
Size: 16.43 MB - java-21-openjdk-javadoc-zip-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: 4c1f3c95fea86b7ef58b10f941c15dcd
SHA-256: db0e417e21f35a3758ad7a39d2d2078accc80e9f0be02490e9712f9abc3e88dd
Size: 41.55 MB - java-21-openjdk-jmods-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: 371794df9d9e528d89e351e88ce32b0f
SHA-256: 4768938757717b0fc5ae1604c3ae331070f958cdd65b6219b6fab782af658cf1
Size: 308.99 MB - java-21-openjdk-jmods-fastdebug-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: 8287042e94eea4fb7853d00272d18594
SHA-256: 30b28185a62d8931ab792acaf04f9472c80ca03b39366fa3431f14775fd35466
Size: 364.03 MB - java-21-openjdk-jmods-slowdebug-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: 59bae70e825bd705840b83547aa70ff3
SHA-256: 15813a262731faf6cfbf1c43816f28c5d43d552ca32937abef6549410d85d8ea
Size: 285.99 MB - java-21-openjdk-slowdebug-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: 60b500dd73bcf4062f0c8fdc6076d382
SHA-256: 4f024b6ca3c8c7b026d1ade465523786bc9ba89b07c2b106f59337ae1e985ed6
Size: 447.50 kB - java-21-openjdk-src-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: 45952fc248bc29b19155e3afe8d8ec44
SHA-256: 17c45e2efdccb2ee8385b7de2fcfced1891305b9e9cdde33eab0eaa6997f904b
Size: 47.46 MB - java-21-openjdk-src-fastdebug-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: 9cdcc83f5396bbeeb090a94978474775
SHA-256: 8a5a10cc37e71301a87192e351b8a8d40ff6b67b588f8f1fa4d15cb9d52eeda6
Size: 47.47 MB - java-21-openjdk-src-slowdebug-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: f51508a8123ad81bd09ee79c37456a96
SHA-256: 889e3d6dc93569b6cd675e8ad27785ba27c095d783c8485a932e9954fa8f8b0f
Size: 47.47 MB - java-21-openjdk-static-libs-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: 57853dad8855f470df7a34552e1fa632
SHA-256: c4662c302a06b38fe2cc7350134cf15663273cdfcd525df429f61be7d6a19723
Size: 34.35 MB - java-21-openjdk-static-libs-fastdebug-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: 5e2f3000694b0f593112cc4820cf5955
SHA-256: f721bd3cc78529b7627abf66fde3eff8fbc9646c5d7fddcc354e05e314fdedaa
Size: 34.49 MB - java-21-openjdk-static-libs-slowdebug-21.0.12.0.8-1.1.el8.ML.1.x86_64.rpm
MD5: 77ac61b987e24147b902edc2af6575f9
SHA-256: 7a49a67495bdb618269b97a74e1cc0a5209362b9f7e23e608a8469baec179d8e
Size: 27.97 MB