java-25-openjdk-25.0.4.1.1-1.1.el9.ML.1
エラータID: AXSA:2026-1741:09
The OpenJDK 25 packages provide the OpenJDK 25 Java Runtime Environment and the
OpenJDK 25 Java Software Development Kit.
Security Fix(es):
JDK: Improve Resource Resolving (CVE-2026-60589)
JDK: Enhance HTTP Connections (CVE-2026-61308)
JDK: Improve font loading (CVE-2026-70906)
JDK: Enhance TLS server (CVE-2026-70907)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.
CVE(s):
CVE-2026-60589
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
CVE-2026-61308
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).
CVE-2026-70906
Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-70907
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Update packages.
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).
Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
N/A
SRPMS
- java-25-openjdk-25.0.4.1.1-1.1.el9.ML.1.src.rpm
MD5: 2e1a9f1ab4f780fbc66ac0369b14fffd
SHA-256: e8ecdfa148b7d15d7c57ac3355d3b82bca42d1c3e3f5fc5eb9d9845c24869782
Size: 73.98 MB
Asianux Server 9 for x86_64
- java-25-openjdk-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: d34a25298de5d03200a82e7805064700
SHA-256: 1ed1355c977c4caf37106aed56942304e277b57cc36f8448d971a08e36c88cc4
Size: 389.54 kB - java-25-openjdk-crypto-adapter-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: 087e3cc5553ad1c409cd5a5b4e155e28
SHA-256: 1939ad5bae8c78601276bf1925253e5c65aee5ec05cef8b544edf03fcb05bb78
Size: 49.63 kB - java-25-openjdk-crypto-adapter-fastdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: c11a630441afaefb38b99d97eeca6f23
SHA-256: c799591c968cd564bf0fff7a6ce319bbb0bfc166a63950623fde6942bad5ca53
Size: 49.82 kB - java-25-openjdk-crypto-adapter-slowdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: ea65e1d0dc31895f4b7a635c1902d57d
SHA-256: 465a00535cb0b98352187273a31d4d75a308718b1e98a59c5f077f1ab071cd16
Size: 50.56 kB - java-25-openjdk-demo-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: 749b6745f98172204ed93a961237a0be
SHA-256: 0238e70af6f94b18dceb031f5d861f13b37676551dea0627f928ca6fcaffd405
Size: 3.16 MB - java-25-openjdk-demo-fastdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: b3afc1f03d22863ae4f080910fede3a3
SHA-256: d43d16a7bafbdacd859b2ffb15aabdd440cb73d6b2d2a94c3c8e9f18719c17ad
Size: 3.16 MB - java-25-openjdk-demo-slowdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: cb61f2a521706c28bfa49541f1059e79
SHA-256: 3fc3ece3df2fc6ab0e4ad3715b399b0b8cc46b09a99c117efb54d075a8802fe2
Size: 3.16 MB - java-25-openjdk-devel-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: 7aaa3b867cccca8e25518aa9c2601571
SHA-256: 2aa4a757c7a1274928c15c4e2b70b2591258f6f619b9ac65e0d6e8044042c0b4
Size: 6.05 MB - java-25-openjdk-devel-fastdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: e73ee13e547baf72f1b5b28b0c550d86
SHA-256: e34714cf84797f059adbcb153b26c835ce4589a763ae7a18e8de73030c18408c
Size: 6.05 MB - java-25-openjdk-devel-slowdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: 6290f04655ad45a588d40b08166baffe
SHA-256: 5052b87f5203b2ea3c2f8e74691a660c50de99a40c14ca5ff65968f3bc1d5084
Size: 6.05 MB - java-25-openjdk-fastdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: c1eb3b82c2c0d53943426db8e5cbfbaf
SHA-256: 36a63c782e0a4a3b2db62e555c298c23d12479360b39f5eaa145a486a9760f2e
Size: 397.79 kB - java-25-openjdk-headless-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: b6b6387ad23595ca69871ef50d888b83
SHA-256: a1116d72fe995389c61f1fcbf0390da4e643cedee21618b5991f76eeeed52680
Size: 59.18 MB - java-25-openjdk-headless-fastdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: e49a4e366ca7d0bdc349ea92e07b368e
SHA-256: 51a1b899f712f6fb3f293d3b44b14b7a559dcca94bfc6ae06812f05f4b24855b
Size: 64.36 MB - java-25-openjdk-headless-slowdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: 1479ce0ae8aec98d3d08d969688e1616
SHA-256: 0ca3947e21062a7af8e21b786c37895660284c1a317b26db0b669d82a6c27774
Size: 62.23 MB - java-25-openjdk-javadoc-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: 176256914b4676db37db2e68af86b1a8
SHA-256: 557138c599cd47c9675b9d9d5b8c2c325583185ae31d1c4867f450f1e93e2fda
Size: 19.86 MB - java-25-openjdk-javadoc-zip-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: a297b7c6b5180e2e0b03bda5a484f44c
SHA-256: 726cd7f54bbfa17a659484b324799fa06c49375e765cda26d355698e384b5e58
Size: 47.88 MB - java-25-openjdk-jmods-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: bd356f27b300f49a55f167f9322321af
SHA-256: dd8a353614aeba84b4984a3d1a5de8e1e6d29700fdff7ef91d807aee3f3de17a
Size: 347.59 MB - java-25-openjdk-jmods-fastdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: 420e052b7bf31417f6f7c3f59da9f97a
SHA-256: b85b335adfd0870ccff4405e98a143918a81c227bd0f890d71e3433e777f02ce
Size: 409.10 MB - java-25-openjdk-jmods-slowdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: c5e905235d8c0e41f68b19fab607a486
SHA-256: 80ad154d1ddb5b43aae71bcefb677fa384057c03f8122804e618699c771345dc
Size: 309.76 MB - java-25-openjdk-slowdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: 89382c36c68a219c1ea8d6e171a7c5e2
SHA-256: bd3780dce274df6d1d2071ba39567fd6013d57aa4438d00353b7f1b653b14d63
Size: 402.31 kB - java-25-openjdk-src-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: fa5b9baa41c1ca9558e45460a8801378
SHA-256: 6fc1b6c614929ca9ee285a7d0d7b42c9163e1e870f234d3c4a1068f80216eb9f
Size: 46.22 MB - java-25-openjdk-src-fastdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: f4e592fa115e3ebe0661785d4f8f0de2
SHA-256: 764aca100fd3f4c5c4fe3598e228a24d1450ba504f84be1aaffb6b2048c5eaa2
Size: 46.22 MB - java-25-openjdk-src-slowdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: 9ff17d80c3a1906d6199801e93d17ed1
SHA-256: bfd912a66ebbda97a863f5c9c46ce3ef53e9d2573d2430b14c3fe4b5a1bd6bba
Size: 46.22 MB - java-25-openjdk-static-libs-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: dae35dfe41994e058908203793c66407
SHA-256: 2ec39df7b64655d35f512f5c1cd127778b2d644ec9b7f55d41aa49ecd48462c0
Size: 32.51 MB - java-25-openjdk-static-libs-fastdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: e3dac4b9a9eb570ed4713c677963eb83
SHA-256: 520a8588bd4793688d85754dfec12f500e5ac08d1183af5489f44c3e25cfe4dc
Size: 32.57 MB - java-25-openjdk-static-libs-slowdebug-25.0.4.1.1-1.1.el9.ML.1.x86_64.rpm
MD5: dd545b1e50e15919b410fb76c5f40269
SHA-256: 780c3c5f37fa0a121b3936793ea4ee60cc2e20850ae49cdd6f4a07430e132c53
Size: 22.40 MB