Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

openSUSE Leap 15.6: SUSE-SU-2025:0279-1 moderate: java-21-openjdk

opensuse
Calendar Grey January 29, 2025
Scroller Opensuse
A recent security patch for java-21-openjdk on openSUSE addresses a vulnerability with a moderate risk level associated with a specific CVE identification.
An update that solves one vulnerability can now be installed.

Description

This update for java-21-openjdk fixes the following issues:

Upgrade to upstream tag jdk-21.0.6+7 (January 2025 CPU)

Security fixes:

* CVE-2025-21502: Enhance array handling (JDK-8330045, bsc#1236278)

Other changes:

* JDK-6942632: Hotspot should be able to use more than 64 logical processors

on Windows

* JDK-8028127: Regtest java/security/Security/SynchronizedAccess.java is

incorrect

* JDK-8195675: Call to insertText with single character from custom Input

Method ignored

* JDK-8207908: JMXStatusTest.java fails assertion intermittently

* JDK-8225220: When the Tab Policy is checked,the scroll button direction

displayed incorrectly.

* JDK-8240343: JDI stopListening/stoplis001 "FAILED: listening is successfully

stopped without starting listening"

* JDK-8283214: [macos] Screen magnifier does not show the magnified text for

JComboBox

* JDK-8296787: Unify debug printing format of X.509 cert serial numbers

* JDK-8296972: [macos13]

...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.6

zypper in -t patch SUSE-2025-279=1 openSUSE-SLE-15.6-2025-279=1

* Basesystem Module 15-SP6

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-279=1

Package List

* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)

* java-21-openjdk-21.0.6.0-150600.3.9.1

* java-21-openjdk-src-21.0.6.0-150600.3.9.1

* java-21-openjdk-devel-debuginfo-21.0.6.0-150600.3.9.1

* java-21-openjdk-headless-21.0.6.0-150600.3.9.1

* java-21-openjdk-headless-debuginfo-21.0.6.0-150600.3.9.1

* java-21-openjdk-jmods-21.0.6.0-150600.3.9.1

* java-21-openjdk-devel-21.0.6.0-150600.3.9.1

* java-21-openjdk-debuginfo-21.0.6.0-150600.3.9.1

* java-21-openjdk-debugsource-21.0.6.0-150600.3.9.1

* java-21-openjdk-demo-21.0.6.0-150600.3.9.1

* openSUSE Leap 15.6 (noarch)

* java-21-openjdk-javadoc-21.0.6.0-150600.3.9.1

* Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64)

* java-21-openjdk-21.0.6.0-150600.3.9.1

* java-21-openjdk-devel-debuginfo-21.0.6.0-150600.3.9.1

* java-21-openjdk-headless-21.0.6.0-150600.3.9.1

* java-21-openjdk-headless-debuginfo-21.0.6.0-150600.3.9.1

* java-21-openjdk-devel-21.0.6.0-150600.3.9.1

* java-21-openjdk-debuginfo-21.0.6.0-150600.3.9.1

*...

Read the Full Advisory

References

* bsc#1236278

## References:

* https://www.suse.com/security/cve/CVE-2025-21502.html

* https://bugzilla.suse.com/show_bug.cgi?id=1236278

Announcement ID: SUSE-SU-2025:0279-1
Release Date: 2025-01-28T23:47:05Z
Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.