java-17-openjdk-17.0.20.0.8-1.2.el9.ML.1

エラータID: AXSA:2026-1630:13

Release date: 
Monday, August 24, 2026 - 15:01
Subject: 
java-17-openjdk-17.0.20.0.8-1.2.el9.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The java-17-openjdk packages provide the OpenJDK 17 Java Runtime Environment and
the OpenJDK 17 Java Software Development Kit.

Security Fix(es):

JDK: Enhance TLS certificate handling (CVE-2026-46968)
JDK: Improve DTLS handshaking (CVE-2026-46917)
JDK: Enhance JPEG handling (CVE-2026-47010)
JDK: Enhance XBM image support (CVE-2026-47021)
JDK: Enhance Jar file processing (CVE-2026-47027)
JDK: Improve certification checking (CVE-2026-60147)
JDK: Enhance AWT ImagingLib (CVE-2026-47059)
JDK: Enhance Jar handling (CVE-2026-47063)
JDK: Update LCMS to 2.19 (CVE-2026-41254)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

CVE(s):
CVE-2026-46968
Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
CVE-2026-46917
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
CVE-2026-47010
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
CVE-2026-47021
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
CVE-2026-47027
Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
CVE-2026-60147
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
CVE-2026-47059
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
CVE-2026-47063
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
CVE-2026-41254
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. java-17-openjdk-17.0.20.0.8-1.2.el9.ML.1.src.rpm
    MD5: 3cfe5cd56a7b59430769d100c5a51c55
    SHA-256: 7d4d2d5f7c8edf7adf355adfd45d51bf6bfa6bec047fb845017f798b8e496029
    Size: 64.39 MB

Asianux Server 9 for x86_64
  1. java-17-openjdk-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 2d6e9cad1fbd09199892c602ea1b4217
    SHA-256: 173d11a7081a398c91d07b8f1e1a78de5be1c8024bd4b9fbf5846bc9d61a2682
    Size: 428.49 kB
  2. java-17-openjdk-demo-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 0f53d1b682ee519208a544b1b43e1b4f
    SHA-256: b1b9b78aeaedea8268f86d5bd5bf1d5cf21805b1922db3c45b1ace9efbee44aa
    Size: 3.43 MB
  3. java-17-openjdk-demo-fastdebug-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 879925205523826f0c555fd9fafac330
    SHA-256: bb1310e0921d50b60dcbf28225fba85422db741d059cea63c5f0c6fa3f533305
    Size: 3.43 MB
  4. java-17-openjdk-demo-slowdebug-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 836d0fd65d89cf5e2a0e502ce2bbfece
    SHA-256: fd791c5c253f4e4adc8918f589c87187a06bc56623f4c1a4f5442d0956c7129d
    Size: 3.43 MB
  5. java-17-openjdk-devel-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 47dd284dfd051c6e414694e987155b9d
    SHA-256: 815538e814d837a8da210cf1c4a433f218d1cbc5c4aa26e37ce2dce97b9a8c66
    Size: 4.72 MB
  6. java-17-openjdk-devel-fastdebug-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 0188d00e5ec93debe0cf762359b246ed
    SHA-256: 44515ffe4a7def8104124ce9eddf7634de1204341528e7491e9b6de7f25912ba
    Size: 4.71 MB
  7. java-17-openjdk-devel-slowdebug-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 837efbb2dd000d2a4945b142cfd91c41
    SHA-256: eb94d72cfc6093c106df3715337cb448c882a32a643056b42ec742f04ae2a289
    Size: 4.72 MB
  8. java-17-openjdk-fastdebug-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 6d31798456ffceb372ea34ee1870e616
    SHA-256: 2dbb28ae8d96542d8acb7fdfaf5305f511b45b130e7f5a5ea8a7fabdaa75c6ce
    Size: 437.27 kB
  9. java-17-openjdk-headless-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 407ffbcf2ebfc5dc752d0c1e39ac8818
    SHA-256: acac31b45cc6cc21872c48a1f53fb563d8cc99e89d8e88261c07c69a76f37d30
    Size: 44.33 MB
  10. java-17-openjdk-headless-fastdebug-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: a62688d0c18021b3494bbc3730ebeebd
    SHA-256: 10bf349e389d77b1be0b8f41ade2adf4d80b6e412e9cd2e133e8f02cf1d5ef7f
    Size: 49.31 MB
  11. java-17-openjdk-headless-slowdebug-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 0889755b75ff0d1b228c22ee17b65407
    SHA-256: 8c5f3f24de1d360dffd0b719e82d6af39e8976ccf0df9f14450d53669fcc049c
    Size: 46.17 MB
  12. java-17-openjdk-javadoc-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 24244febf8025ea46f2e54d6ca2fddbe
    SHA-256: 3c9ba33d03a670fe82763ace9413cba6e856bd6e5c5c131081e362d441174051
    Size: 14.68 MB
  13. java-17-openjdk-javadoc-zip-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 6c3070960651c410a6d112afeac38338
    SHA-256: ed372449ad3c963bacea01b53eed5cce062077b837020e55c9fa29ae2ee520f0
    Size: 39.47 MB
  14. java-17-openjdk-jmods-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 49a3025143fbba3757eb421acb166bdc
    SHA-256: 499126e73860a3cb0ae07d8a6e912e51cf9432045ee853abe2befa2eb3b71768
    Size: 246.39 MB
  15. java-17-openjdk-jmods-fastdebug-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 447fd8176e0411895c9daa47b20561f8
    SHA-256: bb170b903c4ee85179e62b149dfd824c60510e2a9967ad739f42708c9d60663c
    Size: 244.83 MB
  16. java-17-openjdk-jmods-slowdebug-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 93e0893d40db476c82493b054aba3b39
    SHA-256: 5b7e0ea4cb6166993034e20bcaaa326a9ff08c3d767b2fa73dbf7dae7c320c93
    Size: 174.84 MB
  17. java-17-openjdk-slowdebug-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 784413eddc2cab02544915ce75732064
    SHA-256: 710367f8dad3ef2dd3646bd3da65a4366001ec747844dd27c806b5ebcd771280
    Size: 407.93 kB
  18. java-17-openjdk-src-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 2405de37d1ce62e68ef1c61388746c91
    SHA-256: c056d19b663023fa6dd1a007e6d83ae8ce62ae265474af1b01d9878cb3cb2faa
    Size: 44.93 MB
  19. java-17-openjdk-src-fastdebug-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 0f2755e3d9338306a68c821a76a58275
    SHA-256: 5a7a31974cb22ff919b9791eeb030aba4b2dc85a1db91d189c9160114b813c91
    Size: 44.93 MB
  20. java-17-openjdk-src-slowdebug-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 7956c1ebf12f8b1d1cc82b2734e66ed1
    SHA-256: 8288cfb5d6528208f061bd77c2fc2c47fdc98af7507a3a71b7af6b9253cef60a
    Size: 44.93 MB
  21. java-17-openjdk-static-libs-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 70b8a21883574a91f8674843046b0b4e
    SHA-256: 5ca8f71881299897a523a84d06344ff2d9f8fd67975216ffd156bab4dfbe2af5
    Size: 29.23 MB
  22. java-17-openjdk-static-libs-fastdebug-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 3cd411a06d708bf877a45d6e1854300b
    SHA-256: c9596f711f71df28263cd098498e1c838cd93d1249286c99c79266e1d60c4ddf
    Size: 29.31 MB
  23. java-17-openjdk-static-libs-slowdebug-17.0.20.0.8-1.2.el9.ML.1.x86_64.rpm
    MD5: 817f0241fba50fee574e4431e2fe3ebe
    SHA-256: 62ecf5590c50b6e6eb0ac8c94d371779dc0210f028c253b34314dd9a2b1dcf00
    Size: 22.96 MB