Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian Trixie OpenJDK Important Man-in-the-Middle Attacks DSA-6119-1

debian
Calendar Grey February 5, 2026
Debian Logo
OpenJDK updates fix major issues, enhancing protection against attacks like CRLF injection in Debian's trixie distribution.
Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect certificate validation, CRLF injection or man-in-the-middle attacks

Summary

For the stable distribution (trixie), these problems have been fixed in
version 25.0.2+10-1~deb13u2. This version of OpenJDK now also requires
jtreg8 for running the testsuite, which has been backported into trixie
as 8.1+1+ds1-1~deb13u1.

We recommend that you upgrade your openjdk-25 packages.

For the detailed security status of openjdk-25 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/openjdk-25

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: openjdk-25
CVE ID: CVE-2026-21925 CVE-2026-21932 CVE-2026-21933 CVE-2026-21945

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here