java-21-openjdk-21.0.12.1.1-1.2.el9.ML.1

エラータID: AXSA:2026-1672:10

Release date: 
Thursday, August 27, 2026 - 12:26
Subject: 
java-21-openjdk-21.0.12.1.1-1.2.el9.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The OpenJDK 21 packages provide the OpenJDK 21 Java Runtime Environment and the
OpenJDK 21 Java Software Development Kit.

Security Fix(es):

JDK: Improve Resource Resolving (CVE-2026-60589)
JDK: Enhance HTTP Connections (CVE-2026-61308)
JDK: Enhance TLS server (CVE-2026-70907)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

CVE(s):
CVE-2026-60589
CVE-2026-61308
CVE-2026-70907
->
CVE-2026-60589
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
CVE-2026-61308
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).
CVE-2026-70907
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. java-21-openjdk-21.0.12.1.1-1.2.el9.ML.1.src.rpm
    MD5: 5a53d8a96b093e406b881c8dd5bbdc1a
    SHA-256: 292ce22c68acbfd26028065a7a9d7d873cce6e08c63d92d763206c0e31c3aa63
    Size: 68.12 MB

Asianux Server 9 for x86_64
  1. java-21-openjdk-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: 6a383ff7c16b29bb60591295930d49b5
    SHA-256: cefd510e944d1c1fa6513a9a0ef3837fc2e8de413e07760e8b6d856b56d1375c
    Size: 400.75 kB
  2. java-21-openjdk-demo-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: 5fcbe3aa1f3327972c2ec8c0352103c2
    SHA-256: 38223b92ee974c58669442320f0fef603cfff17918d1987ca1f57974a78aee38
    Size: 3.20 MB
  3. java-21-openjdk-demo-fastdebug-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: e0774da749eb4901a79675a9ce2b4647
    SHA-256: 7fe48c9f1fa7eb60bff677d0ca1acee0e17141decb68a56f1f14d27707abcef5
    Size: 3.20 MB
  4. java-21-openjdk-demo-slowdebug-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: e7f94dd256fac4520d2bfca73b983d31
    SHA-256: 458a2e64ba4fbc30a845974c7715f3e1e2ebaa608c3b8a50ca4cb386e2288666
    Size: 3.20 MB
  5. java-21-openjdk-devel-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: 85504ee646c3df7fa2b90146487eef62
    SHA-256: b0f412eadfc5685dc78af6029649591266d1583535ef9c8c12ee09bb1d3e6c1d
    Size: 5.00 MB
  6. java-21-openjdk-devel-fastdebug-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: 4980467e5c8e84d1069350febaae8ae3
    SHA-256: 595bae6d58bdbd319d6c0661da70a79f97c24905195d321f622f83d81ba45a29
    Size: 5.01 MB
  7. java-21-openjdk-devel-slowdebug-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: b72b27f517bea003289e0257efde7bd0
    SHA-256: 30e1972f4dd20633da218a91dd7fce311bacdb4daf965363c07b778290092e2b
    Size: 5.01 MB
  8. java-21-openjdk-fastdebug-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: f7bf41d6af02acdb4ac58bf52d2ca1e7
    SHA-256: a9026b707b1e1b08141e5b0c84c1a2146fd5dc9a3c3d8751f80c2371b6d9c98f
    Size: 409.40 kB
  9. java-21-openjdk-headless-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: 0cf72e67d4605a9c740fb20655652a96
    SHA-256: 7c21531dd203bf2a75ba110a7cc235fc277f433b48e0e8d2046b8364a2557f7e
    Size: 47.51 MB
  10. java-21-openjdk-headless-fastdebug-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: 67974d17125473df4e2bdd350c7c21cb
    SHA-256: 96bcc7578621820cc331f6b0aa648f462f5ddecce175c96dfa28c17a9fc11372
    Size: 52.03 MB
  11. java-21-openjdk-headless-slowdebug-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: 9e20a41b595601a81915722e0bdf4b67
    SHA-256: 1ddd61439da2a17d735ab18d700971d100236d10dbce4df00d76bbcb2e185e18
    Size: 50.07 MB
  12. java-21-openjdk-javadoc-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: 7b4657ddb94868822e36fc424a6ccde4
    SHA-256: d0a40f4aea324b66356188a2bf5b7860274496c6cd51c16de3bebce7f1a98fe9
    Size: 14.99 MB
  13. java-21-openjdk-javadoc-zip-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: c18d7a2f24e308e85b914b2974c7a400
    SHA-256: ceca02d46bf29714b6aa1b691ef5a6efa83392cbef54e64a2154a3848a28cd5c
    Size: 40.64 MB
  14. java-21-openjdk-jmods-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: 71736d50088731fc7b1d90d8e44cf15f
    SHA-256: 1010f0b3bce2d763f727087d23992470efc44c72c0061b3a2958eb8c420ce430
    Size: 304.19 MB
  15. java-21-openjdk-jmods-fastdebug-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: 2a4619016b59851928c0b03dfbb89570
    SHA-256: fa3acb114fc8d404cd6a4691ab2c10a745e57fcfb8d60a10bd985c935fe8a63d
    Size: 355.33 MB
  16. java-21-openjdk-jmods-slowdebug-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: deb467160b239a31da17942371057c3b
    SHA-256: 4f5993ea52dd39c216fb3cea46286ad4c88b559fd2737c3040f465e4b2274a89
    Size: 270.50 MB
  17. java-21-openjdk-slowdebug-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: de2dc645c2152d307794f7ae7a9ed2da
    SHA-256: 7527ff2a4340ceae77104d74281d40795725850f8156915c17570f70e711e383
    Size: 409.77 kB
  18. java-21-openjdk-src-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: e3c5c839c8e013919db6cc96b32802a7
    SHA-256: 347a5b220948e07ab5763a49d2a7d969dcb96cd1387910e402af24aa65546345
    Size: 46.81 MB
  19. java-21-openjdk-src-fastdebug-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: 55cebf7df98417103cee42112c059fbd
    SHA-256: 38e2a0657d52452d656083157748b08cd719fc99507544fc7d01353fc9ee4581
    Size: 46.81 MB
  20. java-21-openjdk-src-slowdebug-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: b2c2687914ebbca3b8d5959002508848
    SHA-256: d742d20b327d7a18f03b30b27d763dec643d7705863df05c4daad09575381afa
    Size: 46.81 MB
  21. java-21-openjdk-static-libs-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: 6a19f29de5df91e1e330ce4f7c32b14f
    SHA-256: f203d4c6d19052d9b261af524b29e1e4f441a54b471c95cb9ccca21001a3c3ea
    Size: 31.36 MB
  22. java-21-openjdk-static-libs-fastdebug-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: d6baecfb4712b3f44f69897a818ba257
    SHA-256: edf548ef5dfa438bdd02f151c2d4894ebcb25067fa9cda77650c7de65b9e6e5d
    Size: 31.61 MB
  23. java-21-openjdk-static-libs-slowdebug-21.0.12.1.1-1.2.el9.ML.1.x86_64.rpm
    MD5: b5567aabda94c471eeb37013591d71e4
    SHA-256: 3d1e00e27ce4513779d9de221b620aeda861adf66eccaff9fc7508e248437d66
    Size: 22.74 MB