Several security issues were fixed in OpenJDK 11.
Software Description:
- openjdk-lts: Open Source Java implementation
Details:
It was discovered that the RMI component of OpenJDK 11 would establish
RMI TCP endpoint connections to a remote host without setting an
endpoint identification algorithm. An unauthenticated remote attacker
could possibly use this issue to steal sensitive information.
(CVE-2026-21925)
Mingijung discovered that the AWT and JavaFX componenets of OpenJDK 11
could run programs if Desktop.browse() was supplied a filename as a
URI. An unauthenticated remote attacker could possibly use this issue
to execute arbitrary code. (CVE-2026-21932)
Zhihui Chen discovered that the Networking component of OpenJDK 11
was suceptible to a CRLF injection vulnerability via the HttpServer
class. An unauthenticated remote attacker could possibly use this
issue to modify files or leak sensitive information. (CVE-2026-21933)
Ireneusz Pastusiak discovered that the Security compo...
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 25.10
openjdk-11-jdk 11.0.30+7-1ubuntu1~25.10
openjdk-11-jdk-headless 11.0.30+7-1ubuntu1~25.10
openjdk-11-jre 11.0.30+7-1ubuntu1~25.10
openjdk-11-jre-headless 11.0.30+7-1ubuntu1~25.10
openjdk-11-jre-zero 11.0.30+7-1ubuntu1~25.10
Ubuntu 24.04 LTS
openjdk-11-jdk 11.0.30+7-1ubuntu1~24.04
openjdk-11-jdk-headless 11.0.30+7-1ubuntu1~24.04
openjdk-11-jre 11.0.30+7-1ubuntu1~24.04
openjdk-11-jre-headless 11.0.30+7-1ubuntu1~24.04
openjdk-11-jre-zero 11.0.30+7-1ubuntu1~24.04
Ubuntu 22.04 LTS
openjdk-11-jdk 11.0.30+7-1ubuntu1~22.04
openjdk-11-jdk-headless 11.0.30+7-1ubuntu1~22.04
openjdk-11-jre 11.0.30+7-1ubuntu1~22.04
openjdk-11-jre-headless 11.0.30+7-1ubuntu1~22.04
openjdk-11-jre-zero 11.0.30+7-1ubuntu1~22.04
Ubuntu 20.04 LTS
openjdk-11-jdk 11.0.30+7-1ubuntu1~20.04
Available with Ubuntu Pro
openjdk-11-jdk-headless 11.0.30+7-1ubuntu1~20.04
Available with Ubuntu Pro
openjdk-11-jre 11.0.30+7-1ubuntu1~20.04
Available with Ubuntu Pro
openjdk-11-jre-headless 11.0.30+7-1ubuntu1~20.04
Available with Ubuntu Pro
openjdk-11-jre-zero 11.0.30+7-1ubuntu1~20.04
Available with Ubuntu Pro
Ubuntu 18.04 LTS
openjdk-11-jdk 11.0.30+7-1ubuntu1~18.04
Available with Ubuntu Pro
openjdk-11-jdk-headless 11.0.30+7-1ubuntu1~18.04
Available with Ubuntu Pro
openjdk-11-jre 11.0.30+7-1ubuntu1~18.04
Available with Ubuntu Pro
openjdk-11-jre-headless 11.0.30+7-1ubuntu1~18.04
Available with Ubuntu Pro
openjdk-11-jre-zero 11.0.30+7-1ubuntu1~18.04
Available with Ubuntu Pro
This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart Java
applications to make all the necessary changes.https://ubuntu.com/security/notices/USN-8001-1
CVE-2026-21925, CVE-2026-21932, CVE-2026-21933, CVE-2026-21945
Get the latest Linux and open source security news straight to your inbox.