java-21-openjdk-21.0.12.0.8-1.2.el9.ML.1
エラータID: AXSA:2026-1580:09
The OpenJDK 21 packages provide the OpenJDK 21 Java Runtime Environment and the
OpenJDK 21 Java Software Development Kit.
Security Fix(es):
JDK: Enhance TLS certificate handling (CVE-2026-46968)
JDK: Improve DTLS handshaking (CVE-2026-46917)
JDK: Enhance JPEG handling (CVE-2026-47010)
JDK: Enhance XBM image support (CVE-2026-47021)
JDK: Enhance Jar file processing (CVE-2026-47027)
JDK: Improve certification checking (CVE-2026-60147)
JDK: Enhance AWT ImagingLib (CVE-2026-47059)
JDK: Enhance Jar handling (CVE-2026-47063)
JDK: Update LCMS to 2.19 (CVE-2026-41254)
Enhancement(s):
For the last couple of years, OpenJDK has used a single build shared among
multiple RPMs and a tarball available on the customer portal. The single
"portable" build has a release number ('p') and each RPM has its own release
number ('r'). However, the RPM naming only showed the RPM release number, while
the version output from the build showed the portable release number, making it
unclear that they were different numbers. From this release onwards, a release
field of the form 'p.r' is always used for RPMs and the version output shows
'p'. (RHEL-212337, RHEL-212338, RHEL-212339, RHEL-212340, RHEL-212342,
RHEL-212343)
Bug Fix(es):
In previous releases, the RPM did not correctly own the subdirectories used
for documentation in /usr/share/doc and /usr/share/javadoc. This is fixed in
this release, so these subdirectories will be removed when the package is
uninstalled. (RHEL-212353, RHEL-212359, RHEL-212360, RHEL-212361)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.
CVE(s):
CVE-2026-46968
CVE-2026-46917
CVE-2026-47010
CVE-2026-47021
CVE-2026-47027
CVE-2026-60147
CVE-2026-47059
CVE-2026-47063
CVE-2026-41254
Update packages.
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
N/A
SRPMS
- java-21-openjdk-21.0.12.0.8-1.2.el9.ML.1.src.rpm
MD5: dbdb3aad268556d81e722ea6862a0db9
SHA-256: 199203818d6e31e78c6cb679a8f053a6ef8a0c85abd3b8d79c28cbaacde03d29
Size: 67.96 MB
Asianux Server 9 for x86_64
- java-21-openjdk-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: b3c9402269174f423f542ae2ec32b3d3
SHA-256: 0f86b62261c89e87697f737e19c23f83359b56ab9183b4f9c2aef8fce45e54e1
Size: 400.29 kB - java-21-openjdk-demo-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: f5b8f5ffdebbfbe2320f76aef8a79fa7
SHA-256: fec11a65bb75e9eaf3162fbb6ded29bb4529cdc91c04a637db37b434f0108349
Size: 3.19 MB - java-21-openjdk-demo-fastdebug-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: 5c9d39020907a94561a8d5a562d34a8d
SHA-256: 173ac2ab30c6dd2fcd868b0554624c0b7fd624452b88de772ed1ba4843a290a3
Size: 3.20 MB - java-21-openjdk-demo-slowdebug-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: e95293fa1979dadad412b61bebbf2348
SHA-256: 919e41f5a4c56fde51ea7c35f4f90fa129cdba8632be50b974b99d607d57fa74
Size: 3.20 MB - java-21-openjdk-devel-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: c826a1f40adc0b16bc9594bc7605ac66
SHA-256: 73e9fc25331a7de48ed561ccc57fc49253670e9a29fec35448f2484e0848df3f
Size: 5.00 MB - java-21-openjdk-devel-fastdebug-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: b3d8be9e555e34800e9d351221d9e0cb
SHA-256: d424317ced642009f03c93dc9c630937dbf679cd527bbfdb1504efbfe80dffd6
Size: 5.01 MB - java-21-openjdk-devel-slowdebug-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: 5fe40f387232144fa504e0b408cd98c6
SHA-256: e8225b5d7a72dc722796826cafa00c395fd0541dd57e055ebe72b0803edb5b50
Size: 5.01 MB - java-21-openjdk-fastdebug-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: 38d62157f885e13480d861b7a3595916
SHA-256: b93ef3b2bd52c328793b3dacbe993f64991722738fad9a9770771d1604122f69
Size: 408.85 kB - java-21-openjdk-headless-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: 2e8a03c889f14122b141a5e120181e1b
SHA-256: 84e34281b39cebeb33973179d0f41f37c28ca2c347622b2b93733b2ebcd7dbc1
Size: 47.51 MB - java-21-openjdk-headless-fastdebug-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: 3eb754e5737d4ff57c0e601dc47d7c66
SHA-256: 482bd1b153ed77b010a4549f09f2bbe023490a6a7ac4b76a6107adf7a353d4f7
Size: 52.02 MB - java-21-openjdk-headless-slowdebug-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: 5ac499f079ceb0baae5f59d5d58493f4
SHA-256: 61804d72325c3556b1a5ffbfcc81e8d8a88b3b47cadfed296975bd75d882590f
Size: 50.12 MB - java-21-openjdk-javadoc-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: 0ed54a1c8c51c7ae88bfad961a38ddb1
SHA-256: 90e1da848fa357e48fdb6feeb638f914bf5d124385dd1efe0129fde861d12c56
Size: 14.99 MB - java-21-openjdk-javadoc-zip-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: f17075cd8ec2e7655316f086ab67354c
SHA-256: 3a56337c0354d5146c5e9cd975c89380fc7a78c5c5c6266d177daf2123755a44
Size: 40.60 MB - java-21-openjdk-jmods-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: 1e67deaed9c54b1ab086dbccedbf9e7d
SHA-256: 4e3d775d3ea37eb2ee95ba8230b22564a8131bf0016fd80e57d79f98179a6682
Size: 304.16 MB - java-21-openjdk-jmods-fastdebug-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: 7d5f2006deb20d82c8f566bbdcdc5804
SHA-256: 4ddfbe7867bb3d4ae4b67d3e10eab5c5373545ca77e5f5ee1a988724082cc9df
Size: 355.37 MB - java-21-openjdk-jmods-slowdebug-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: b42276c6024d981c4a003cf1019266e8
SHA-256: 07959d5f647da7a9a4b985fdd120d9c3eb289c71b70c6a590b7548dfba2a0596
Size: 270.43 MB - java-21-openjdk-slowdebug-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: c6fae004514762c670ea0e616272f4c2
SHA-256: 7d016feae0c3ecc211a4518127641327cac7748f9a8a4f2888b7399fa03f3f27
Size: 409.27 kB - java-21-openjdk-src-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: dcda0d39f0d40db451f40725cc1f60f7
SHA-256: 2e5a34fdd5f0fb2860c1d73f4502af507b871104a36925df35c72344372e8184
Size: 46.81 MB - java-21-openjdk-src-fastdebug-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: e3d9b4600b479ee72486121b096a6ffd
SHA-256: 1d778c35c933f73646ccffddf446cf6043b7d55383ddbb61e5fbe327c1364443
Size: 46.81 MB - java-21-openjdk-src-slowdebug-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: d3d27619bf5a0806b2c1abaac0ac2852
SHA-256: 69d22495350e1574bf476da4a5f878e9457a4f323d28b5c3606de421dc6cb1d8
Size: 46.81 MB - java-21-openjdk-static-libs-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: fa2d4b5a170a039d3d82e2c7d83e4913
SHA-256: b91f023b44fa1625e82685e822513b5f7569a3fd1553a5def7b872d96cb56792
Size: 31.46 MB - java-21-openjdk-static-libs-fastdebug-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: e4d72ee76859f409484dba671f71863e
SHA-256: db6969135e235be7f19df2596e63edf697aefb803e79ac2d58abe89589c70ff6
Size: 31.64 MB - java-21-openjdk-static-libs-slowdebug-21.0.12.0.8-1.2.el9.ML.1.x86_64.rpm
MD5: 9e545bfd4977ecb9321a89b6d122c678
SHA-256: 8b2a0747c80868d599355b6581b06b54135fc5bfc944a785863495574dd80822
Size: 22.76 MB