java-25-openjdk-25.0.4.0.7-1.1.el9.ML.1

エラータID: AXSA:2026-1651:08

Release date: 
Wednesday, August 26, 2026 - 11:34
Subject: 
java-25-openjdk-25.0.4.0.7-1.1.el9.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The OpenJDK 25 packages provide the OpenJDK 25 Java Runtime Environment and the
OpenJDK 25 Java Software Development Kit.

Security Fix(es):

JDK: Enhance TLS certificate handling (CVE-2026-46968)
JDK: Improve DTLS handshaking (CVE-2026-46917)
JDK: Enhance JPEG handling (CVE-2026-47010)
JDK: Enhance XBM image support (CVE-2026-47021)
JDK: Enhance Jar file processing (CVE-2026-47027)
JDK: Improve certification checking (CVE-2026-60147)
JDK: Enhance AWT ImagingLib (CVE-2026-47059)
JDK: Enhance Jar handling (CVE-2026-47063)
JDK: Update LCMS to 2.19 (CVE-2026-41254)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

CVE(s):

CVE-2026-46968
Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
CVE-2026-46917
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
CVE-2026-47010
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
CVE-2026-47021
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
CVE-2026-47027
Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
CVE-2026-60147
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
CVE-2026-47059
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
CVE-2026-47063
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
CVE-2026-41254
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. java-25-openjdk-25.0.4.0.7-1.1.el9.ML.1.src.rpm
    MD5: 0b24aa2cea216e422272359784c3b1d3
    SHA-256: feef18c9af316afe2b2539b603062e286b1433db5999a50dd64b8271cdd716a8
    Size: 73.97 MB

Asianux Server 9 for x86_64
  1. java-25-openjdk-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: 55cad8cbf29762b117efaba627238b45
    SHA-256: 7cd3e2d3ba94857d940d0484c3e674566138f42812d586de71a4b3e8a4f99b60
    Size: 389.03 kB
  2. java-25-openjdk-crypto-adapter-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: e0efa95cb8773eab7855a12886c612fe
    SHA-256: eb4a02e7f45eda4cae6af36ba6f4874ef792d2aa1efc7e879c7852cd663ef3f6
    Size: 49.08 kB
  3. java-25-openjdk-crypto-adapter-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: fb2a1c370a88ebde00e3a1e83fb62c41
    SHA-256: 65a3f6ed792ca16bc174752981d155e9ef0e4859806168422751c4b48f54c36f
    Size: 49.27 kB
  4. java-25-openjdk-crypto-adapter-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: da3c97ce1e6f7919ddc8aca2b262a98e
    SHA-256: 85212dfa4eaccc1de981b8735c14c2ec6a6de8b7f0fe44db0f489acc1a1d35b5
    Size: 49.88 kB
  5. java-25-openjdk-demo-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: 982afd47622b2b62eaa67bb351faa58b
    SHA-256: ec69071fe617122ff3cacec2ef1385ee64f919e3018baaafe704dcca19c04415
    Size: 3.16 MB
  6. java-25-openjdk-demo-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: bcf07c1e91c083387e6c1c3382641226
    SHA-256: 49e4ea0acc8247cbdc0a20a215d1cfb61d5aefa76c1ae8881f5cc948308d02d7
    Size: 3.16 MB
  7. java-25-openjdk-demo-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: 6b07f39ad3c746a25992adf2e12c9394
    SHA-256: ee2328feae75037d016fe521c17202127b5d29312b09262dfbff1dfe0d769b97
    Size: 3.16 MB
  8. java-25-openjdk-devel-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: 8de3a3eeb886f130ba493a3e8b195edb
    SHA-256: 4c05461d4656a7ad0027a9b25e3db013700e2897b8116256791cf7a1ecdafad3
    Size: 6.05 MB
  9. java-25-openjdk-devel-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: ad727b4061ca418fcd03e0786bab1aca
    SHA-256: a97a2cd680b29d2fa458ee6ef6e103c7327d92df2b6390925f3f2bcb34fec951
    Size: 6.05 MB
  10. java-25-openjdk-devel-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: 92efcc2df575ee58d10bce08033f508b
    SHA-256: 4e538a61f5b2a9ebdd52b88ffde554ba6191b5bbfd9bc45b47b7f84d416acff0
    Size: 6.05 MB
  11. java-25-openjdk-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: 83fb314dfc6d16e222e116381d3e0a6b
    SHA-256: de10d9e07a61a6c87a71acab8c3562b99a2af2c26e63c3dc95ba8e50e8a4d33b
    Size: 397.22 kB
  12. java-25-openjdk-headless-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: 47b09eb14bff3ea8f62b49ef5c9df50c
    SHA-256: 4382fc84b945a48cc6aad0cd43b2d27291ae7c0b81a3471991a01ad1e1124dec
    Size: 59.16 MB
  13. java-25-openjdk-headless-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: e1a6202d6e0ea6126aa8cc6d62112d88
    SHA-256: 3b906613ea350ade11474c19a21d44148fa5d6205734d97b54b71d31ed9ced00
    Size: 64.37 MB
  14. java-25-openjdk-headless-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: 6c2b45cb72206b282dc0ed175aa634a3
    SHA-256: ee9b15588bb313fb98a66e85cfbd37fccf64eb059757073a338501d38e180c05
    Size: 62.27 MB
  15. java-25-openjdk-javadoc-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: 1f5a8c8d6ed1a04b6b12cd4e64688878
    SHA-256: e17c6901f772f48d0336595bf1e5778afcf32a51ab7845214417ea51a8ee8d7e
    Size: 19.86 MB
  16. java-25-openjdk-javadoc-zip-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: b1e311abee3f7a4a863fcf5d50400fcf
    SHA-256: a2c661939c0cce88e682ea6ffa09997cb9771b86b53812c718cbcc6b8f1b2904
    Size: 47.89 MB
  17. java-25-openjdk-jmods-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: 6bc8bd13205cadc8b7caf10078f2a99b
    SHA-256: 044e7c58bf8e88a15aaaab9435705c6cb853a6db058b142d6510c7437cb9da1f
    Size: 347.59 MB
  18. java-25-openjdk-jmods-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: a6e684600b852f05abc2bf8b2198152a
    SHA-256: 48162bbda6315f59660fecd4db0326dd5c833c0542894c2e54978efaf3a44c80
    Size: 409.15 MB
  19. java-25-openjdk-jmods-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: 9a1b30060d660a12a94421645ee82821
    SHA-256: d86d0a37d1c345ab5c1ef717d1ff72644725aac020b9868239e63b47060701c4
    Size: 309.77 MB
  20. java-25-openjdk-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: e6e5eb2eb284f6053a7bf6d79f1de616
    SHA-256: 86bb115e2c497f157ae7cfefec5bea8aa033c6fcdff8eed7f0c37b38bf007883
    Size: 399.46 kB
  21. java-25-openjdk-src-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: a90fae82040a64167693cee4d68d3294
    SHA-256: 183be6f7fb2772d24a9187e766ad60938278f0b9bdd5be5b57626dba5651d623
    Size: 46.22 MB
  22. java-25-openjdk-src-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: d6baa38f8fadace74338b61749d43c9e
    SHA-256: 7ee7af82637fa124d753f7355dbf567764a0a9f7e049d01236cda1d210985ebd
    Size: 46.22 MB
  23. java-25-openjdk-src-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: 22f808125831f38bf700970c33d78b43
    SHA-256: 84675a46be634b5bcef63fbfe6a49971a5828ae9d12a025e836e13b7f72c446d
    Size: 46.22 MB
  24. java-25-openjdk-static-libs-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: 9953e9ebd23d19e6234679d7503fea82
    SHA-256: a2d66dfbc73662beeb6d3a5dea0d68883795a4868e34ae5b0ef1eb9229eb0b96
    Size: 32.54 MB
  25. java-25-openjdk-static-libs-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: 78588784e66676f036973d66024e4eac
    SHA-256: 037215719deaa79323acb8d4878ef212a5a0498d860a68cb420b8235040b7e39
    Size: 32.55 MB
  26. java-25-openjdk-static-libs-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
    MD5: adcd05da5a7f394f180df58f09c36952
    SHA-256: e37c334b74dad09c14eb34f447c8137829ba17dd175629237ec4cd7ff1928ede
    Size: 22.43 MB