Alerts This Week
Warning Icon 1 449
Alerts This Week
Warning Icon 1 449

openSUSE java-17-openj9 Important Remote Access Issues Fixed 2026-0208-1

opensuse
Calendar Grey June 15, 2026
Dist Opensuse Esm H88
Update for openSUSE java-17-openj9 resolves 15 vulnerabilities with one feature included. Learn more here.
An update that solves 15 vulnerabilities, contains one feature and has one errata is now available.

Description

This update for java-17-openj9 fixes the following issues:

- Make post scripts less noisy (boo#1267355)

- Use libalternatives instead of update-alternatives for distributions

where libalternatives is available

- Update to OpenJDK 17.0.19 with OpenJ9 0.59.0 virtual machine

- Including Oracle April 2026 CPU changes

* CVE-2026-22007 (boo#1262490), CVE-2026-22013 (boo#1262494),

CVE-2026-22016 (boo#1262495), CVE-2026-22018 (boo#1262496),

CVE-2026-22021 (boo#1262497), CVE-2026-23865 (boo#1259118),

CVE-2026-34268 (boo#1262500), CVE-2026-34282 (boo#1262501)

- OpenJ9 specific security fix

* CVE-2026-1188 (boo#1265261)

* OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.59/

- Update to OpenJDK 17.0.18 with OpenJ9 0.57.0 virtual machine

- Including Oracle January 2026 CPU changes

* CVE-2026-21925 (boo#1257034), CVE-2026-21932 (boo#1257036),

CVE-2026-21933 (boo#1257037), CVE-2026-21945 (boo#1257038)

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-208=1

Package List

- openSUSE Backports SLE-15-SP7 (aarch64 ppc64le s390x x86_64):

java-17-openj9-17.0.19.0-bp157.2.6.1

java-17-openj9-demo-17.0.19.0-bp157.2.6.1

java-17-openj9-devel-17.0.19.0-bp157.2.6.1

java-17-openj9-headless-17.0.19.0-bp157.2.6.1

java-17-openj9-jmods-17.0.19.0-bp157.2.6.1

java-17-openj9-src-17.0.19.0-bp157.2.6.1

- openSUSE Backports SLE-15-SP7 (noarch):

java-17-openj9-javadoc-17.0.19.0-bp157.2.6.1

References

https://www.suse.com/security/cve/CVE-2025-53057.html

https://www.suse.com/security/cve/CVE-2025-53066.html

https://www.suse.com/security/cve/CVE-2026-1188.html

https://www.suse.com/security/cve/CVE-2026-21925.html

https://www.suse.com/security/cve/CVE-2026-21932.html

https://www.suse.com/security/cve/CVE-2026-21933.html

https://www.suse.com/security/cve/CVE-2026-21945.html

https://www.suse.com/security/cve/CVE-2026-22007.html

https://www.suse.com/security/cve/CVE-2026-22013.html

https://www.suse.com/security/cve/CVE-2026-22016.html

https://www.suse.com/security/cve/CVE-2026-22018.html

https://www.suse.com/security/cve/CVE-2026-22021.html

https://www.suse.com/security/cve/CVE-2026-23865.html

https://www.suse.com/security/cve/CVE-2026-34268.html

https://www.suse.com/security/cve/CVE-2026-34282.html

https://bugzilla.suse.com/1252414

https://bugzilla.suse.com/1252417

https://bugzilla.suse.com/1257034

https://bugzilla.suse.com/1257036

https://bugzilla.suse.com/1257037

https://bugzilla.suse.com/1257038

https://...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:0208-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP7 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here