Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Mageia 9: 2025-0156 critical: Fixes for Java TLS and compiler issues

mageia
Calendar Grey May 13, 2025
Dist Mageia Esm H88
The latest security advisory from Mageia addresses essential updates to the Java package, aimed at mitigating various vulnerabilities and enhancing feature support.
Better TLS connection support

Summary

Better TLS connection support. (CVE-2025-21587) Improve compiler transformations. (CVE-2025-30691) Enhance Buffered Image handling. (CVE-2025-30698) The updated timezone data are needed by the new Java packages.

References

- https://bugs.mageia.org/show_bug.cgi?id=34206

- https://access.redhat.com/errata/RHSA-2025:3845

- https://access.redhat.com/errata/RHSA-2025:3850

- https://access.redhat.com/errata/RHSA-2025:3853

- https://access.redhat.com/errata/RHSA-2025:3856

- https://www.oracle.com/security-alerts/cpuapr2025.html#AppendixJAVA

- https://www.cve.org/CVERecord?id=CVE-2025-21587

- https://www.cve.org/CVERecord?id=CVE-2025-30691

- https://www.cve.org/CVERecord?id=CVE-2025-30698

Resolution

SRPMS

- 9/core/timezone-2025a-1.mga9

- 9/core/java-1.8.0-openjdk-1.8.0.452.b09-1.mga9

- 9/core/java-11-openjdk-11.0.27.0.6-1.mga9

- 9/core/java-17-openjdk-17.0.15.0.6-1.mga9

- 9/core/java-latest-openjdk-24.0.1.0.9-1.rolling.1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 13 May 2025
URL: https://advisories.mageia.org/MGASA-2025-0156.html
Type: security
CVE: CVE-2025-21587, CVE-2025-30691, CVE-2025-30698

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here