java-25-openjdk-25.0.4.0.7-1.1.el9.ML.1
エラータID: AXSA:2026-1651:08
The OpenJDK 25 packages provide the OpenJDK 25 Java Runtime Environment and the
OpenJDK 25 Java Software Development Kit.
Security Fix(es):
JDK: Enhance TLS certificate handling (CVE-2026-46968)
JDK: Improve DTLS handshaking (CVE-2026-46917)
JDK: Enhance JPEG handling (CVE-2026-47010)
JDK: Enhance XBM image support (CVE-2026-47021)
JDK: Enhance Jar file processing (CVE-2026-47027)
JDK: Improve certification checking (CVE-2026-60147)
JDK: Enhance AWT ImagingLib (CVE-2026-47059)
JDK: Enhance Jar handling (CVE-2026-47063)
JDK: Update LCMS to 2.19 (CVE-2026-41254)
Enhancement(s):
For the last couple of years, OpenJDK has used a single build shared among
multiple RPMs and a tarball available on the customer portal. The single
"portable" build has a release number ('p') and each RPM has its own release
number ('r'). However, the RPM naming only showed the RPM release number, while
the version output from the build showed the portable release number, making it
unclear that they were different numbers. From this release onwards, a release
field of the form 'p.r' is always used for RPMs and the version output shows
'p'. (RHEL-211046, RHEL-211048)
Bug Fix(es):
The performance of the Math.pow function regressed between OpenJDK 8 and
OpenJDK 11. This was due to an absence of constant folding when applicable (for
example, Math.pow(2,1) being replaced by 2). This release reintroduces this
optimization. (RHEL-211050, RHEL-211052)
On RHEL 9 systems, the alternatives list a JDK and architecture pair (for
example, "java-11-openjdk.x86_64") followed by the path to the binary in
brackets. RHEL 10 systems have a simpler format that just lists the path.
Because the OpenJDK 25 packages for RHEL 9 were originally based on those from
RHEL 10, they used the simpler format. With this release, the format for OpenJDK
25 packages on RHEL 9 is updated to be closer to other JDKs on that platform.
(RHEL-212650)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.
CVE(s):
CVE-2026-46968
CVE-2026-46917
CVE-2026-47010
CVE-2026-47021
CVE-2026-47027
CVE-2026-60147
CVE-2026-47059
CVE-2026-47063
CVE-2026-41254
Update packages.
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
N/A
SRPMS
- java-25-openjdk-25.0.4.0.7-1.1.el9.ML.1.src.rpm
MD5: 0b24aa2cea216e422272359784c3b1d3
SHA-256: feef18c9af316afe2b2539b603062e286b1433db5999a50dd64b8271cdd716a8
Size: 73.97 MB
Asianux Server 9 for x86_64
- java-25-openjdk-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: 55cad8cbf29762b117efaba627238b45
SHA-256: 7cd3e2d3ba94857d940d0484c3e674566138f42812d586de71a4b3e8a4f99b60
Size: 389.03 kB - java-25-openjdk-crypto-adapter-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: e0efa95cb8773eab7855a12886c612fe
SHA-256: eb4a02e7f45eda4cae6af36ba6f4874ef792d2aa1efc7e879c7852cd663ef3f6
Size: 49.08 kB - java-25-openjdk-crypto-adapter-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: fb2a1c370a88ebde00e3a1e83fb62c41
SHA-256: 65a3f6ed792ca16bc174752981d155e9ef0e4859806168422751c4b48f54c36f
Size: 49.27 kB - java-25-openjdk-crypto-adapter-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: da3c97ce1e6f7919ddc8aca2b262a98e
SHA-256: 85212dfa4eaccc1de981b8735c14c2ec6a6de8b7f0fe44db0f489acc1a1d35b5
Size: 49.88 kB - java-25-openjdk-demo-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: 982afd47622b2b62eaa67bb351faa58b
SHA-256: ec69071fe617122ff3cacec2ef1385ee64f919e3018baaafe704dcca19c04415
Size: 3.16 MB - java-25-openjdk-demo-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: bcf07c1e91c083387e6c1c3382641226
SHA-256: 49e4ea0acc8247cbdc0a20a215d1cfb61d5aefa76c1ae8881f5cc948308d02d7
Size: 3.16 MB - java-25-openjdk-demo-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: 6b07f39ad3c746a25992adf2e12c9394
SHA-256: ee2328feae75037d016fe521c17202127b5d29312b09262dfbff1dfe0d769b97
Size: 3.16 MB - java-25-openjdk-devel-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: 8de3a3eeb886f130ba493a3e8b195edb
SHA-256: 4c05461d4656a7ad0027a9b25e3db013700e2897b8116256791cf7a1ecdafad3
Size: 6.05 MB - java-25-openjdk-devel-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: ad727b4061ca418fcd03e0786bab1aca
SHA-256: a97a2cd680b29d2fa458ee6ef6e103c7327d92df2b6390925f3f2bcb34fec951
Size: 6.05 MB - java-25-openjdk-devel-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: 92efcc2df575ee58d10bce08033f508b
SHA-256: 4e538a61f5b2a9ebdd52b88ffde554ba6191b5bbfd9bc45b47b7f84d416acff0
Size: 6.05 MB - java-25-openjdk-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: 83fb314dfc6d16e222e116381d3e0a6b
SHA-256: de10d9e07a61a6c87a71acab8c3562b99a2af2c26e63c3dc95ba8e50e8a4d33b
Size: 397.22 kB - java-25-openjdk-headless-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: 47b09eb14bff3ea8f62b49ef5c9df50c
SHA-256: 4382fc84b945a48cc6aad0cd43b2d27291ae7c0b81a3471991a01ad1e1124dec
Size: 59.16 MB - java-25-openjdk-headless-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: e1a6202d6e0ea6126aa8cc6d62112d88
SHA-256: 3b906613ea350ade11474c19a21d44148fa5d6205734d97b54b71d31ed9ced00
Size: 64.37 MB - java-25-openjdk-headless-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: 6c2b45cb72206b282dc0ed175aa634a3
SHA-256: ee9b15588bb313fb98a66e85cfbd37fccf64eb059757073a338501d38e180c05
Size: 62.27 MB - java-25-openjdk-javadoc-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: 1f5a8c8d6ed1a04b6b12cd4e64688878
SHA-256: e17c6901f772f48d0336595bf1e5778afcf32a51ab7845214417ea51a8ee8d7e
Size: 19.86 MB - java-25-openjdk-javadoc-zip-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: b1e311abee3f7a4a863fcf5d50400fcf
SHA-256: a2c661939c0cce88e682ea6ffa09997cb9771b86b53812c718cbcc6b8f1b2904
Size: 47.89 MB - java-25-openjdk-jmods-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: 6bc8bd13205cadc8b7caf10078f2a99b
SHA-256: 044e7c58bf8e88a15aaaab9435705c6cb853a6db058b142d6510c7437cb9da1f
Size: 347.59 MB - java-25-openjdk-jmods-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: a6e684600b852f05abc2bf8b2198152a
SHA-256: 48162bbda6315f59660fecd4db0326dd5c833c0542894c2e54978efaf3a44c80
Size: 409.15 MB - java-25-openjdk-jmods-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: 9a1b30060d660a12a94421645ee82821
SHA-256: d86d0a37d1c345ab5c1ef717d1ff72644725aac020b9868239e63b47060701c4
Size: 309.77 MB - java-25-openjdk-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: e6e5eb2eb284f6053a7bf6d79f1de616
SHA-256: 86bb115e2c497f157ae7cfefec5bea8aa033c6fcdff8eed7f0c37b38bf007883
Size: 399.46 kB - java-25-openjdk-src-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: a90fae82040a64167693cee4d68d3294
SHA-256: 183be6f7fb2772d24a9187e766ad60938278f0b9bdd5be5b57626dba5651d623
Size: 46.22 MB - java-25-openjdk-src-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: d6baa38f8fadace74338b61749d43c9e
SHA-256: 7ee7af82637fa124d753f7355dbf567764a0a9f7e049d01236cda1d210985ebd
Size: 46.22 MB - java-25-openjdk-src-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: 22f808125831f38bf700970c33d78b43
SHA-256: 84675a46be634b5bcef63fbfe6a49971a5828ae9d12a025e836e13b7f72c446d
Size: 46.22 MB - java-25-openjdk-static-libs-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: 9953e9ebd23d19e6234679d7503fea82
SHA-256: a2d66dfbc73662beeb6d3a5dea0d68883795a4868e34ae5b0ef1eb9229eb0b96
Size: 32.54 MB - java-25-openjdk-static-libs-fastdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: 78588784e66676f036973d66024e4eac
SHA-256: 037215719deaa79323acb8d4878ef212a5a0498d860a68cb420b8235040b7e39
Size: 32.55 MB - java-25-openjdk-static-libs-slowdebug-25.0.4.0.7-1.1.el9.ML.1.x86_64.rpm
MD5: adcd05da5a7f394f180df58f09c36952
SHA-256: e37c334b74dad09c14eb34f447c8137829ba17dd175629237ec4cd7ff1928ede
Size: 22.43 MB