Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
This update for java-21-openjdk fixes the following issues:
Update to upstream tag jdk-21.0.12+8 (July 2026 CPU).
Security issues fixed:
* CVE-2026-41254: lcms: information disclosure and denial of service via
integer overflow in `CubeSize` (bsc#1264994).
* CVE-2026-46917: unauthenticated attacker with network access via TLS can
cause a partial denial of service (bsc#1272223).
* CVE-2026-46968: unauthenticated attacker with network access via TLS can
gain unauthorized creation, deletion or modification access to critical
data(bsc#1272224).
* CVE-2026-47010: unauthenticated attacker with network access via multiple
protocols can gain unauthorized update, insert or delete access to some data
(bsc#1272225).
* CVE-2026-47021: unauthenticated attacker with network access via multiple
protocols can cause a partial denial of service (bsc#1272227).
* CVE-2026-47027: unauthenticated attacker with network access via multiple
protocols can cause a...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3332=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3332=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3332=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3332=1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* java-21-openjdk-jmods-21.0.12.0-150600.3.29.1
* java-21-openjdk-debugsource-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-21.0.12.0-150600.3.29.1
* java-21-openjdk-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-21.0.12.0-150600.3.29.1
* java-21-openjdk-src-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-demo-21.0.12.0-150600.3.29.1
* openSUSE Leap 15.6 (noarch)
* java-21-openjdk-javadoc-21.0.12.0-150600.3.29.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* java-21-openjdk-devel-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-21.0.12.0-150600.3.29.1
* java-21-openjdk-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-21.0.12.0-150600.3.29.1
* java-21-openjdk-debugsource-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-21.0.12.0-150600.3.29.1
*...
Read the Full Advisory* bsc#1264397
* bsc#1264994
* bsc#1267355
* bsc#1272223
* bsc#1272224
* bsc#1272225
* bsc#1272227
* bsc#1272228
* bsc#1272235
* bsc#1272236
* bsc#1272237
## References:
* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46917.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47021.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47059.html
* https://www.suse.com/security/cve/CVE-2026-47063.html
* https://www.suse.com/security/cve/CVE-2026-60147.html
* https://bugzilla.suse.com/show_bug.cgi?id=1264397
* https://bugzilla.suse.com/show_bug.cgi?id=1264994
* https://bugzilla.suse.com/show_bug.cgi?id=1267355
* https://bugzilla.suse.com/show_bug.cgi?id=1272223
* https://bugzilla.suse.com/show_bug.cgi?id=1272224
* https://bugzilla.suse.com/show_bug.cgi?id=1272225
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.