Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
* bsc#1246806 * bsc#1252414 * bsc#1252417 * bsc#1252418 . # Security update for java-21-openjdk Announcement ID: SUSE-SU-2025:21162-1 Release Date: 2025-11-28T09:35:08Z Rating: important References: * bsc#1246806 * bsc#1252414 * bsc#1252417 * bsc#1252418 Cross-References: * CVE-2025-53057 * CVE-2025-53066 * CVE-2025-61748 CVSS scores: * CVE-2025-53057 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-53057 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53057 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53066 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-53066 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-53066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-61748 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-61748 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-61748 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves three vulnerabilities and has one fix can now be installed. ## Description: This update for java-21-openjdk fixes the following issues: Update to upstream tag jdk-21.0.9+10 (October 2025 CPU): * CVE-2025-53066: Fixed enhance path factories (bsc#1252417). * CVE-2025-61748: Fixed enhance string handling (bsc#1252418). * CVE-2025-53057: Fixed enhance certificate handling (bsc#1252414). Other bug fixes: * Do not embed rebuild counter (bsc#1246806) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patchSUSE-SLES-16.0-82=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-82=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * java-21-openjdk-21.0.9.0-160000.1.1 * java-21-openjdk-src-21.0.9.0-160000.1.1 * java-21-openjdk-devel-21.0.9.0-160000.1.1 * java-21-openjdk-devel-debuginfo-21.0.9.0-160000.1.1 * java-21-openjdk-debuginfo-21.0.9.0-160000.1.1 * java-21-openjdk-demo-21.0.9.0-160000.1.1 * java-21-openjdk-headless-debuginfo-21.0.9.0-160000.1.1 * java-21-openjdk-headless-21.0.9.0-160000.1.1 * java-21-openjdk-jmods-21.0.9.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * java-21-openjdk-javadoc-21.0.9.0-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * java-21-openjdk-21.0.9.0-160000.1.1 * java-21-openjdk-src-21.0.9.0-160000.1.1 * java-21-openjdk-devel-21.0.9.0-160000.1.1 * java-21-openjdk-devel-debuginfo-21.0.9.0-160000.1.1 * java-21-openjdk-debuginfo-21.0.9.0-160000.1.1 * java-21-openjdk-demo-21.0.9.0-160000.1.1 * java-21-openjdk-headless-debuginfo-21.0.9.0-160000.1.1 * java-21-openjdk-headless-21.0.9.0-160000.1.1 * java-21-openjdk-jmods-21.0.9.0-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (noarch) * java-21-openjdk-javadoc-21.0.9.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-53057.html * https://www.suse.com/security/cve/CVE-2025-53066.html * https://www.suse.com/security/cve/CVE-2025-61748.html * https://bugzilla.suse.com/show_bug.cgi?id=1246806 * https://bugzilla.suse.com/show_bug.cgi?id=1252414 * https://bugzilla.suse.com/show_bug.cgi?id=1252417 * https://bugzilla.suse.com/show_bug.cgi?id=1252418 . SUSE security update for java-21-openjdk addresses multiple issues with important severity and patch instructions.. SUSE Security Update, Java 21 OpenJDK, Important Security Fix, Cybersecurity Linux. . Severity: Important.LinuxSecurity.com Team
* bsc#1246806 * bsc#1252414 * bsc#1252417 Cross-References: . # Security update for java-17-openjdk Announcement ID: SUSE-SU-2025:21164-1 Release Date: 2025-11-28T10:27:02Z Rating: important References: * bsc#1246806 * bsc#1252414 * bsc#1252417 Cross-References: * CVE-2025-53057 * CVE-2025-53066 CVSS scores: * CVE-2025-53057 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-53057 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53057 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53066 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-53066 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-53066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for java-17-openjdk fixes the following issues: Upgrade to upstream tag jdk-17.0.17+10 (October 2025 CPU): * CVE-2025-53066: Fixed enhance path factories (bsc#1252417). * CVE-2025-53057: Fixed enhance certificate handling (bsc#1252414). Other bug fixes: * Do not embed rebuild counter (bsc#1246806). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-84=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-84=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * java-17-openjdk-jmods-17.0.17.0-160000.1.1 * java-17-openjdk-headless-17.0.17.0-160000.1.1 *java-17-openjdk-devel-debuginfo-17.0.17.0-160000.1.1 * java-17-openjdk-demo-17.0.17.0-160000.1.1 * java-17-openjdk-debuginfo-17.0.17.0-160000.1.1 * java-17-openjdk-headless-debuginfo-17.0.17.0-160000.1.1 * java-17-openjdk-src-17.0.17.0-160000.1.1 * java-17-openjdk-devel-17.0.17.0-160000.1.1 * java-17-openjdk-17.0.17.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * java-17-openjdk-javadoc-17.0.17.0-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * java-17-openjdk-jmods-17.0.17.0-160000.1.1 * java-17-openjdk-headless-17.0.17.0-160000.1.1 * java-17-openjdk-devel-debuginfo-17.0.17.0-160000.1.1 * java-17-openjdk-demo-17.0.17.0-160000.1.1 * java-17-openjdk-debuginfo-17.0.17.0-160000.1.1 * java-17-openjdk-headless-debuginfo-17.0.17.0-160000.1.1 * java-17-openjdk-src-17.0.17.0-160000.1.1 * java-17-openjdk-devel-17.0.17.0-160000.1.1 * java-17-openjdk-17.0.17.0-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (noarch) * java-17-openjdk-javadoc-17.0.17.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-53057.html * https://www.suse.com/security/cve/CVE-2025-53066.html * https://bugzilla.suse.com/show_bug.cgi?id=1246806 * https://bugzilla.suse.com/show_bug.cgi?id=1252414 * https://bugzilla.suse.com/show_bug.cgi?id=1252417 . The SUSE java-17-openjdk update addresses important vulnerabilities, enhancing security and certificate handling.. SUSE, java-17-openjdk, certificate handling, security update. . Severity: Important. LinuxSecurity.com Team
An update that solves 3 vulnerabilities and has 4 bug fixes can now be installed.. openSUSE security update: security update for java-21-openjdk ------------------------------------------------------------- Announcement ID: openSUSE-SU-2025-20123-1 Rating: important References: * bsc#1246806 * bsc#1252414 * bsc#1252417 * bsc#1252418 Cross-References: * CVE-2025-53057 * CVE-2025-53066 * CVE-2025-61748 CVSS scores: * CVE-2025-53057 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53057 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-53066 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-53066 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-61748 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-61748 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has 4 bug fixes can now be installed. Description: This update for java-21-openjdk fixes the following issues: Update to upstream tag jdk-21.0.9+10 (October 2025 CPU): - CVE-2025-53066: Fixed enhance path factories (bsc#1252417). - CVE-2025-61748: Fixed enhance string handling (bsc#1252418). - CVE-2025-53057: Fixed enhance certificate handling (bsc#1252414). Other bug fixes: - Do not embed rebuild counter (bsc#1246806) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-82=1 Package List: - openSUSE Leap 16.0: java-21-openjdk-21.0.9.0-160000.1.1 java-21-openjdk-demo-21.0.9.0-160000.1.1 java-21-openjdk-devel-21.0.9.0-160000.1.1 java-21-openjdk-headless-21.0.9.0-160000.1.1 java-21-openjdk-javadoc-21.0.9.0-160000.1.1 java-21-openjdk-jmods-21.0.9.0-160000.1.1 java-21-openjdk-src-21.0.9.0-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2025-53057.html * https://www.suse.com/security/cve/CVE-2025-53066.html * https://www.suse.com/security/cve/CVE-2025-61748.html . Important security update for openSUSE Java 21 to resolve critical issues, ensuring robust system integrity and performance.. important update, openSUSE security, java application, security patches. . Severity: Important. LinuxSecurity.com Team
An update that solves 2 vulnerabilities and has 3 bug fixes can now be installed.. openSUSE security update: security update for java-17-openjdk ------------------------------------------------------------- Announcement ID: openSUSE-SU-2025-20125-1 Rating: important References: * bsc#1246806 * bsc#1252414 * bsc#1252417 Cross-References: * CVE-2025-53057 * CVE-2025-53066 CVSS scores: * CVE-2025-53057 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53057 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-53066 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-53066 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 3 bug fixes can now be installed. Description: This update for java-17-openjdk fixes the following issues: Upgrade to upstream tag jdk-17.0.17+10 (October 2025 CPU): - CVE-2025-53066: Fixed enhance path factories (bsc#1252417). - CVE-2025-53057: Fixed enhance certificate handling (bsc#1252414). Other bug fixes: - Do not embed rebuild counter (bsc#1246806). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-84=1 Package List: - openSUSE Leap 16.0: java-17-openjdk-17.0.17.0-160000.1.1 java-17-openjdk-demo-17.0.17.0-160000.1.1 java-17-openjdk-devel-17.0.17.0-160000.1.1 java-17-openjdk-headless-17.0.17.0-160000.1.1 java-17-openjdk-javadoc-17.0.17.0-160000.1.1 java-17-openjdk-jmods-17.0.17.0-160000.1.1 java-17-openjdk-src-17.0.17.0-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2025-53057.html *https://www.suse.com/security/cve/CVE-2025-53066.html . Addressing vulnerabilities in java-17-openjdk for openSUSE Leap 16.0 with critical security updates and bug fixes.. openSUSE java-17-openjdk security important patch update bug fix. . Severity: Important. LinuxSecurity.com Team
* bsc#1252414 * bsc#1252417 * bsc#1252418 * jsc#PED-14233 . # Security update for java-25-openjdk Announcement ID: SUSE-SU-2025:4287-1 Release Date: 2025-11-28T08:23:45Z Rating: important References: * bsc#1252414 * bsc#1252417 * bsc#1252418 * jsc#PED-14233 Cross-References: * CVE-2025-53057 * CVE-2025-53066 * CVE-2025-61748 CVSS scores: * CVE-2025-53057 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-53057 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53057 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53066 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-53066 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-53066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-61748 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-61748 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-61748 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities and contains one feature can now be installed. ## Description: This update for java-25-openjdk fixes the following issues: Update to upstream tag jdk-25.0.1+8 (October 2025 CPU) * Security fixes: * JDK-8360937, CVE-2025-53057, bsc#1252414: Enhance certificate handling * JDK-8356294, CVE-2025-53066, bsc#1252417: Enhance Path Factories * JDK-8359454, CVE-2025-61748, bsc#1252418: Enhance String handling * JDK-8352637: Enhance bytecode verification * Other fixes: * JDK-8367031: [backout] Change java.time month/day field types to 'byte' * JDK-8368308: ISO 4217 Amendment180 Update * JDK-8366223: ZGC: ZPageAllocator::cleanup_failed_commit_multi_partition is broken * JDK-8360647: [XWayland] [OL10] NumPad keys are not triggered * JDK-8361212: Remove AffirmTrust root CAs * JDK-8356587: Missing object ID X in pool jdk.types.Method * JDK-8360679: Shenandoah: AOT saved adapter calls into broken GC barrier stub * JDK-8362882: Update SubmissionPublisher() specification to reflect use of ForkJoinPool.asyncCommonPool() * JDK-8315131: Clarify VarHandle set/get access on 32-bit platforms * JDK-8362109: Change milestone to fcs for all releases * JDK-8358819: The first year is not displayed correctly in Japanese Calendar * JDK-8361829: [TESTBUG] RISC-V: compiler/vectorization/runner/ /BasicIntOpTest.java fails with RVV but not Zvbb * JDK-8361532: RISC-V: Several vector tests fail after JDK-8354383 * JDK-8357826: Avoid running some jtreg tests when asan is configured * JDK-8358577: Test serviceability/jvmti/thread/ /GetCurrentContendedMonitor/contmon01/contmon01.java failed: unexpexcted monitor object * JDK-8360533: ContainerRuntimeVersionTestUtils fromVersionString fails with some docker versions * JDK-8358452: JNI exception pending in Java_sun_awt_screencast_ScreencastHelper_remoteDesktopKeyImpl of screencast_pipewire.c:1214 (ID: 51119) * JDK-8359270: C2: alignment check should consider base offset when emitting arraycopy runtime call * JDK-8359596: Behavior change when both -Xlint:options and -Xlint:-options flags are given * JDK-8360179: RISC-V: Only enable BigInteger intrinsics when AvoidUnalignedAccess == false * JDK-8359218: RISC-V: Only enable CRC32 intrinsic when AvoidUnalignedAccess == false * JDK-8359059: Bump version numbers for 25.0.1 * forward port the FIPS support from OpenJDK 21 * Initial packaging of OpenJDK 25 * JEPs included: * 470: PEM Encodings of Cryptographic Objects (Preview) * 502: Stable Values (Preview) * 503: Remove the 32-bit x86 Port * 505: StructuredConcurrency (Fifth Preview) * 506: Scoped Values * 507: Primitive Types in Patterns, instanceof, and switch (Third Preview) * 508: Vector API (Tenth Incubator) * 509: JFR CPU-Time Profiling (Experimental) * 510: Key Derivation Function API * 511: Module Import Declarations * 512: Compact Source Files and Instance Main Methods * 513: Flexible Constructor Bodies * 514: Ahead-of-Time Command-Line Ergonomics * 515: Ahead-of-Time Method Profiling * 518: JFR Cooperative Sampling * 519: Compact Object Headers * 520: JFR Method Timing & Tracing * 521: Generational Shenandoah ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-4287=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-25-openjdk-debuginfo-25.0.1.0-150700.15.4.1 * java-25-openjdk-headless-debuginfo-25.0.1.0-150700.15.4.1 * java-25-openjdk-devel-debuginfo-25.0.1.0-150700.15.4.1 * java-25-openjdk-demo-25.0.1.0-150700.15.4.1 * java-25-openjdk-devel-25.0.1.0-150700.15.4.1 * java-25-openjdk-25.0.1.0-150700.15.4.1 * java-25-openjdk-headless-25.0.1.0-150700.15.4.1 ## References: * https://www.suse.com/security/cve/CVE-2025-53057.html * https://www.suse.com/security/cve/CVE-2025-53066.html * https://www.suse.com/security/cve/CVE-2025-61748.html * https://bugzilla.suse.com/show_bug.cgi?id=1252414 * https://bugzilla.suse.com/show_bug.cgi?id=1252417 * https://bugzilla.suse.com/show_bug.cgi?id=1252418 * . Critical update for java-25-openjdk addressing important vulnerabilities and security enhancements as outlined in the advisory.. SUSE Update, java-25-openjdk, Security Enhancements. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for java-1_8_0-openjdk Announcement ID: SUSE-SU-2025:4039-1 Release Date: 2025-11-10T15:05:47Z Rating: important References: * bsc#1252414 * bsc#1252417 Cross-References: * CVE-2025-53057 * CVE-2025-53066 CVSS scores: * CVE-2025-53057 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-53057 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53057 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53066 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-53066 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-53066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Legacy Module 15-SP6 * Legacy Module 15-SP7 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update forjava-1_8_0-openjdk fixes the following issues: Update to version jdk8u472 (icedtea-3.37.0): * CVE-2025-53057: Fixed certificate handling leading to unauthorized creation, deletion or modification access to critical data (bsc#1252414) * CVE-2025-53066: Fixed Path factories leading to unauthorized access to critical data or complete access (bsc#1252417) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-4039=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-4039=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-4039=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-4039=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-4039=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-4039=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-4039=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-4039=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-4039=1 * Legacy Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP6-2025-4039=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2025-4039=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-4039=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patchSUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-4039=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) *java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 *java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-src-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-accessibility-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * openSUSE Leap 15.6 (noarch) * java-1_8_0-openjdk-javadoc-1.8.0.472-150000.3.114.3 * Legacy Module 15-SP6 (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 *java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 ## References: * https://www.suse.com/security/cve/CVE-2025-53057.html * https://www.suse.com/security/cve/CVE-2025-53066.html * https://bugzilla.suse.com/show_bug.cgi?id=1252414 * https://bugzilla.suse.com/show_bug.cgi?id=1252417 . Learn about critical updates for openSUSE regarding java-1_8_0-openjdk that address two important access vulnerabilities.. openSUSE security, java vulnerabilities, system update, software patching. . Severity: Important. LinuxSecurity.com Team
Bing Shi discovered that GnuTLS, a portable library which implements the Transport Layer Security and Datagram Transport Layer Security protocols, had inefficient handling of certificate data with a large number of names or name constraints, potentially leading to Denial of . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4063-1
USN-6237-1 introduced a regression in curl.. =========================================================================Ubuntu Security Notice USN-6237-2 July 19, 2023 curl regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: USN-6237-1 introduced a regression in curl. Software Description: - curl: HTTP, HTTPS, and FTP client and client libraries Details: USN-6237-1 fixed vulnerabilities in curl. The update caused a certificate wildcard handling regression on Ubuntu 22.04 LTS. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Hiroki Kurosawa discovered that curl incorrectly handled validating certain certificate wildcards. A remote attacker could possibly use this issue to spoof certain website certificates using IDN hosts. (CVE-2023-28321) Hiroki Kurosawa discovered that curl incorrectly handled callbacks when certain options are set by applications. This could cause applications using curl to misbehave, resulting in information disclosure, or a denial of service. (CVE-2023-28322) It was discovered that curl incorrectly handled saving cookies to files. A local attacker could possibly use this issue to create or overwrite files. This issue only affected Ubuntu 22.10, and Ubuntu 23.04. (CVE-2023-32001) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: curl 7.81.0-1ubuntu1.13 libcurl3-gnutls 7.81.0-1ubuntu1.13 libcurl3-nss 7.81.0-1ubuntu1.13 libcurl4 7.81.0-1ubuntu1.13 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6237-2 https://ubuntu.com/security/notices/USN-6237-1 https://bugs.launchpad.net/ubuntu/+source/curl/+bug/2028170 Package Information: https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.13 . Ubuntu Security Advisory USN-6237-2 details a curl issue impacting Ubuntu 22.04, addressing critical vulnerabilities.. curl regression, Ubuntu 22.04, security update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.