Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
* bsc#1252414 * bsc#1252417 Cross-References: * CVE-2025-53057 . # Security update for java-1_8_0-openjdk Announcement ID: SUSE-SU-2025:4039-1 Release Date: 2025-11-10T15:05:47Z Rating: important References: * bsc#1252414 * bsc#1252417 Cross-References: * CVE-2025-53057 * CVE-2025-53066 CVSS scores: * CVE-2025-53057 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-53057 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53057 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53066 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-53066 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-53066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Legacy Module 15-SP6 * Legacy Module 15-SP7 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update forjava-1_8_0-openjdk fixes the following issues: Update to version jdk8u472 (icedtea-3.37.0): * CVE-2025-53057: Fixed certificate handling leading to unauthorized creation, deletion or modification access to critical data (bsc#1252414) * CVE-2025-53066: Fixed Path factories leading to unauthorized access to critical data or complete access (bsc#1252417) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-4039=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-4039=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-4039=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-4039=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-4039=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-4039=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-4039=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-4039=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-4039=1 * Legacy Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP6-2025-4039=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2025-4039=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-4039=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patchSUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-4039=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) *java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 *java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-src-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-accessibility-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * openSUSE Leap 15.6 (noarch) * java-1_8_0-openjdk-javadoc-1.8.0.472-150000.3.114.3 * Legacy Module 15-SP6 (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-demo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.472-150000.3.114.3 *java-1_8_0-openjdk-debugsource-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-devel-1.8.0.472-150000.3.114.3 * java-1_8_0-openjdk-debuginfo-1.8.0.472-150000.3.114.3 ## References: * https://www.suse.com/security/cve/CVE-2025-53057.html * https://www.suse.com/security/cve/CVE-2025-53066.html * https://bugzilla.suse.com/show_bug.cgi?id=1252414 * https://bugzilla.suse.com/show_bug.cgi?id=1252417 . Updates for java-1_8_0-openjdk in SUSE fix critical data access issues and enhance security against vulnerabilities.. SUSE Linux security update, Java vulnerabilities, OpenJDK patch, Software security fixes, Critical data access. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for java-1_8_0-openj9 Announcement ID: SUSE-SU-2025:4005-1 Release Date: 2025-11-10T01:04:28Z Rating: important References: * bsc#1252414 * bsc#1252417 Cross-References: * CVE-2025-53057 * CVE-2025-53066 CVSS scores: * CVE-2025-53057 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-53057 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53057 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53066 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-53066 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-53066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for java-1_8_0-openj9 fixes the following issues: Update to OpenJDK 8u472 build 08 with OpenJDK 0.56.0 virtual machine (including Oracle October 2025 CPU changes): * CVE-2025-53057: Fixed unauthenticated attacker achieving unauthorized access to critical data or complete access (bsc#1252414) * CVE-2025-53066: Fixed unauthenticated attacker achieving unauthorized creation, deletion or modification access to critical data (bsc#1252417) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you canrun the command listed for your product: * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-4005=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-4005=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-4005=1 ## Package List: * SUSE Package Hub 15 15-SP6 (ppc64le s390x) * java-1_8_0-openj9-src-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-demo-debuginfo-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-debugsource-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-headless-debuginfo-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-demo-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-devel-debuginfo-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-accessibility-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-debuginfo-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-headless-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-devel-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-1.8.0.472-150200.3.60.3 * SUSE Package Hub 15 15-SP7 (ppc64le s390x) * java-1_8_0-openj9-src-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-demo-debuginfo-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-debugsource-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-headless-debuginfo-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-demo-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-devel-debuginfo-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-accessibility-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-debuginfo-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-headless-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-devel-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-1.8.0.472-150200.3.60.3 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * java-1_8_0-openj9-src-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-demo-debuginfo-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-debugsource-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-headless-debuginfo-1.8.0.472-150200.3.60.3 *java-1_8_0-openj9-demo-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-devel-debuginfo-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-accessibility-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-debuginfo-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-headless-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-devel-1.8.0.472-150200.3.60.3 * java-1_8_0-openj9-1.8.0.472-150200.3.60.3 * openSUSE Leap 15.6 (noarch) * java-1_8_0-openj9-javadoc-1.8.0.472-150200.3.60.3 ## References: * https://www.suse.com/security/cve/CVE-2025-53057.html * https://www.suse.com/security/cve/CVE-2025-53066.html * https://bugzilla.suse.com/show_bug.cgi?id=1252414 * https://bugzilla.suse.com/show_bug.cgi?id=1252417 . An openSUSE update addresses critical vulnerabilities in java-1_8_0-openj9, improving security against data access threats.. openSUSE security, java security, data access security, SUSE update. . Severity: Important. LinuxSecurity.com Team
* bsc#1246806 * bsc#1252414 * bsc#1252417 Cross-References: . # Security update for java-11-openjdk Announcement ID: SUSE-SU-2025:3996-1 Release Date: 2025-11-07T15:49:28Z Rating: important References: * bsc#1246806 * bsc#1252414 * bsc#1252417 Cross-References: * CVE-2025-53057 * CVE-2025-53066 CVSS scores: * CVE-2025-53057 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-53057 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53057 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53066 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-53066 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-53066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Legacy Module 15-SP6 * Legacy Module 15-SP7 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAPApplications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Proxy 4.3 LTS * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Retail Branch Server 4.3 LTS * SUSE Manager Server 4.3 * SUSE Manager Server 4.3 LTS * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for java-11-openjdk fixes the following issues: Upgrade to upstream tag jdk-11.0.29+7 (October 2025 CPU): * CVE-2025-53057: Fixed unauthenticated attacker can achieve unauthorized creation, deletion or modification access to critical data (bsc#1252414). * CVE-2025-53066: Fixed unauthenticated attacker can achive unauthorized access to critical data or complete access (bsc#1252417). Other bug fixes: * Do not embed rebuild counter (bsc#1246806) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Retail Branch Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-LTS-2025-3996=1 * SUSE Manager Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2025-3996=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-3996=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-3996=1 * Legacy Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP6-2025-3996=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2025-3996=1 * SUSE Package Hub 15 15-SP6 zypper in -t patchSUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-3996=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-3996=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-3996=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3996=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3996=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-3996=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-3996=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-3996=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3996=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-3996=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-3996=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3996=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-3996=1 * SUSE Manager Proxy 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2025-3996=1 ## Package List: * SUSE Manager Retail Branch Server 4.3 LTS (x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 *java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Manager Server 4.3 LTS (ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-src-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-jmods-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * openSUSE Leap 15.6 (noarch) * java-11-openjdk-javadoc-11.0.29.0-150000.3.132.2 * Legacy Module 15-SP6 (aarch64 ppc64le s390x x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) *java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Package Hub 15 15-SP6 (noarch) * java-11-openjdk-javadoc-11.0.29.0-150000.3.132.2 * SUSE Package Hub 15 15-SP7 (noarch) * java-11-openjdk-javadoc-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 *java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 *java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * SUSE Manager Proxy 4.3 LTS (x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 ## References: * https://www.suse.com/security/cve/CVE-2025-53057.html * https://www.suse.com/security/cve/CVE-2025-53066.html * https://bugzilla.suse.com/show_bug.cgi?id=1246806 * https://bugzilla.suse.com/show_bug.cgi?id=1252414 * https://bugzilla.suse.com/show_bug.cgi?id=1252417 . Critical security update for java-11-openjdk addressing unauthorized access vulnerabilities in SUSE systems.. Java Update, Access Control, SUSE Security. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities and has one security fix can now be installed.. # Security update for java-11-openjdk Announcement ID: SUSE-SU-2025:3996-1 Release Date: 2025-11-07T15:49:28Z Rating: important References: * bsc#1246806 * bsc#1252414 * bsc#1252417 Cross-References: * CVE-2025-53057 * CVE-2025-53066 CVSS scores: * CVE-2025-53057 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-53057 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53057 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53066 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-53066 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-53066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Legacy Module 15-SP6 * Legacy Module 15-SP7 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE LinuxEnterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Proxy 4.3 LTS * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Retail Branch Server 4.3 LTS * SUSE Manager Server 4.3 * SUSE Manager Server 4.3 LTS * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for java-11-openjdk fixes the following issues: Upgrade to upstream tag jdk-11.0.29+7 (October 2025 CPU): * CVE-2025-53057: Fixed unauthenticated attacker can achieve unauthorized creation, deletion or modification access to critical data (bsc#1252414). * CVE-2025-53066: Fixed unauthenticated attacker can achive unauthorized access to critical data or complete access (bsc#1252417). Other bug fixes: * Do not embed rebuild counter (bsc#1246806) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Retail Branch Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-LTS-2025-3996=1 * SUSE Manager Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2025-3996=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-3996=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-3996=1 * Legacy Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP6-2025-3996=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2025-3996=1 * SUSE Package Hub 15 15-SP6 zypper in -t patchSUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-3996=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-3996=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-3996=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3996=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3996=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-3996=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-3996=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-3996=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3996=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-3996=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-3996=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3996=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-3996=1 * SUSE Manager Proxy 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2025-3996=1 ## Package List: * SUSE Manager Retail Branch Server 4.3 LTS (x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 *java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Manager Server 4.3 LTS (ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-src-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-jmods-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * openSUSE Leap 15.6 (noarch) * java-11-openjdk-javadoc-11.0.29.0-150000.3.132.2 * Legacy Module 15-SP6 (aarch64 ppc64le s390x x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) *java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Package Hub 15 15-SP6 (noarch) * java-11-openjdk-javadoc-11.0.29.0-150000.3.132.2 * SUSE Package Hub 15 15-SP7 (noarch) * java-11-openjdk-javadoc-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 *java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * java-11-openjdk-debuginfo-11.0.29.0-150000.3.132.2 * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 *java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * SUSE Manager Proxy 4.3 LTS (x86_64) * java-11-openjdk-headless-11.0.29.0-150000.3.132.2 * java-11-openjdk-demo-11.0.29.0-150000.3.132.2 * java-11-openjdk-devel-11.0.29.0-150000.3.132.2 * java-11-openjdk-debugsource-11.0.29.0-150000.3.132.2 * java-11-openjdk-11.0.29.0-150000.3.132.2 ## References: * https://www.suse.com/security/cve/CVE-2025-53057.html * https://www.suse.com/security/cve/CVE-2025-53066.html * https://bugzilla.suse.com/show_bug.cgi?id=1246806 * https://bugzilla.suse.com/show_bug.cgi?id=1252414 * https://bugzilla.suse.com/show_bug.cgi?id=1252417 . Solve key issues with Java OpenJDK security in openSUSE. Important HTTP access vulnerabilities fixed. Install the update.. openSUSE security update, Java OpenJDK vulnerabilities, important security patch, openSUSE advisory. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities and has one security fix can now be installed.. # Security update for java-17-openjdk Announcement ID: SUSE-SU-2025:3997-1 Release Date: 2025-11-07T15:51:02Z Rating: important References: * bsc#1246806 * bsc#1252414 * bsc#1252417 Cross-References: * CVE-2025-53057 * CVE-2025-53066 CVSS scores: * CVE-2025-53057 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-53057 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53057 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53066 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-53066 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-53066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP6 * Legacy Module 15-SP6 * Legacy Module 15-SP7 * openSUSE Leap 15.4 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Proxy4.3 LTS * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Retail Branch Server 4.3 LTS * SUSE Manager Server 4.3 * SUSE Manager Server 4.3 LTS An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for java-17-openjdk fixes the following issues: Upgrade to upstream tag jdk-17.0.17+10 (October 2025 CPU): * CVE-2025-53057: Fixed unauthenticated attacker can achieve unauthorized creation, deletion or modification access to critical data (bsc#1252414). * CVE-2025-53066: Fixed unauthenticated attacker can achive unauthorized access to critical data or complete access (bsc#1252417). Other bug fixes: * Do not embed rebuild counter (bsc#1246806) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-3997=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-3997=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-3997=1 * Legacy Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP6-2025-3997=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2025-3997=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3997=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3997=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-3997=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-3997=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patchSUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3997=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-3997=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3997=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-3997=1 * SUSE Manager Proxy 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2025-3997=1 * SUSE Manager Retail Branch Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-LTS-2025-3997=1 * SUSE Manager Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2025-3997=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * java-17-openjdk-devel-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-17.0.17.0-150400.3.60.2 * java-17-openjdk-src-17.0.17.0-150400.3.60.2 * java-17-openjdk-17.0.17.0-150400.3.60.2 * java-17-openjdk-demo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-devel-17.0.17.0-150400.3.60.2 * java-17-openjdk-jmods-17.0.17.0-150400.3.60.2 * java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 * openSUSE Leap 15.4 (noarch) * java-17-openjdk-javadoc-17.0.17.0-150400.3.60.2 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * java-17-openjdk-devel-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-17.0.17.0-150400.3.60.2 * java-17-openjdk-src-17.0.17.0-150400.3.60.2 * java-17-openjdk-17.0.17.0-150400.3.60.2 * java-17-openjdk-demo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-devel-17.0.17.0-150400.3.60.2 * java-17-openjdk-jmods-17.0.17.0-150400.3.60.2 *java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 * openSUSE Leap 15.6 (noarch) * java-17-openjdk-javadoc-17.0.17.0-150400.3.60.2 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * java-17-openjdk-devel-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-17.0.17.0-150400.3.60.2 * java-17-openjdk-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-devel-17.0.17.0-150400.3.60.2 * java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 * Legacy Module 15-SP6 (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 * java-17-openjdk-demo-17.0.17.0-150400.3.60.2 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-17-openjdk-devel-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-17.0.17.0-150400.3.60.2 * java-17-openjdk-17.0.17.0-150400.3.60.2 * java-17-openjdk-demo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-devel-17.0.17.0-150400.3.60.2 * java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * java-17-openjdk-devel-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-17.0.17.0-150400.3.60.2 * java-17-openjdk-17.0.17.0-150400.3.60.2 * java-17-openjdk-demo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-devel-17.0.17.0-150400.3.60.2 * java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) *java-17-openjdk-devel-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-17.0.17.0-150400.3.60.2 * java-17-openjdk-17.0.17.0-150400.3.60.2 * java-17-openjdk-demo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-devel-17.0.17.0-150400.3.60.2 * java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * java-17-openjdk-devel-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-17.0.17.0-150400.3.60.2 * java-17-openjdk-17.0.17.0-150400.3.60.2 * java-17-openjdk-demo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-devel-17.0.17.0-150400.3.60.2 * java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * java-17-openjdk-devel-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-17.0.17.0-150400.3.60.2 * java-17-openjdk-17.0.17.0-150400.3.60.2 * java-17-openjdk-demo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-devel-17.0.17.0-150400.3.60.2 * java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-devel-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-17.0.17.0-150400.3.60.2 * java-17-openjdk-17.0.17.0-150400.3.60.2 * java-17-openjdk-demo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-devel-17.0.17.0-150400.3.60.2 * java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 * SUSE LinuxEnterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-devel-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-17.0.17.0-150400.3.60.2 * java-17-openjdk-17.0.17.0-150400.3.60.2 * java-17-openjdk-demo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-devel-17.0.17.0-150400.3.60.2 * java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-17-openjdk-devel-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-17.0.17.0-150400.3.60.2 * java-17-openjdk-17.0.17.0-150400.3.60.2 * java-17-openjdk-demo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-devel-17.0.17.0-150400.3.60.2 * java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-17-openjdk-devel-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-17.0.17.0-150400.3.60.2 * java-17-openjdk-17.0.17.0-150400.3.60.2 * java-17-openjdk-demo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-devel-17.0.17.0-150400.3.60.2 * java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 * SUSE Manager Proxy 4.3 LTS (x86_64) * java-17-openjdk-devel-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-17.0.17.0-150400.3.60.2 * java-17-openjdk-17.0.17.0-150400.3.60.2 * java-17-openjdk-demo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-devel-17.0.17.0-150400.3.60.2 * java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 * SUSEManager Retail Branch Server 4.3 LTS (x86_64) * java-17-openjdk-devel-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-17.0.17.0-150400.3.60.2 * java-17-openjdk-17.0.17.0-150400.3.60.2 * java-17-openjdk-demo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-devel-17.0.17.0-150400.3.60.2 * java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 * SUSE Manager Server 4.3 LTS (ppc64le s390x x86_64) * java-17-openjdk-devel-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-17.0.17.0-150400.3.60.2 * java-17-openjdk-17.0.17.0-150400.3.60.2 * java-17-openjdk-demo-17.0.17.0-150400.3.60.2 * java-17-openjdk-headless-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-devel-17.0.17.0-150400.3.60.2 * java-17-openjdk-debuginfo-17.0.17.0-150400.3.60.2 * java-17-openjdk-debugsource-17.0.17.0-150400.3.60.2 ## References: * https://www.suse.com/security/cve/CVE-2025-53057.html * https://www.suse.com/security/cve/CVE-2025-53066.html * https://bugzilla.suse.com/show_bug.cgi?id=1246806 * https://bugzilla.suse.com/show_bug.cgi?id=1252414 * https://bugzilla.suse.com/show_bug.cgi?id=1252417 . Update for openSUSE addresses important security issues in java-17-openjdk, enhancing data safety and integrity.. openSUSE java security important update vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves three vulnerabilities and has one security fix can now be installed.. # Security update for java-1_8_0-ibm Announcement ID: SUSE-SU-2025:3965-1 Release Date: 2025-11-06T10:48:06Z Rating: important References: * bsc#1252414 * bsc#1252417 * bsc#1252418 * bsc#1252758 Cross-References: * CVE-2025-53057 * CVE-2025-53066 * CVE-2025-61748 CVSS scores: * CVE-2025-53057 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-53057 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53057 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53066 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-53066 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-53066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-61748 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-61748 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-61748 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Legacy Module 15-SP6 * Legacy Module 15-SP7 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE LinuxEnterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities and has one security fix can now be installed. ## Description: This update for java-1_8_0-ibm fixes the following issues: * CVE-2025-53057: Fixed an issue where an unauthenticated attacker can achieve unauthorized creation, deletion or modification access to critical data (bsc#1252414) * CVE-2025-53066: Fixed an issue where an unauthenticated attacker can achieve unauthorized access to critical data or complete access (bsc#1252417) * CVE-2025-61748: Fixed an issue where an unauthenticated attacker can achieve unauthorized update, insert or delete access to some resources (bsc#1252418) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-3965=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3965=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-3965=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-3965=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3965=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-3965=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-3965=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-3965=1 * Legacy Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP6-2025-3965=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2025-3965=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-3965=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3965=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3965=1 ## Package List: * SUSE Linux Enterprise Server 15 SP3 LTSS (nosrc ppc64le s390x x86_64) * java-1_8_0-ibm-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (ppc64le s390x x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (nosrc ppc64le s390x x86_64) * java-1_8_0-ibm-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (ppc64le s390x x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (nosrc ppc64le s390x x86_64) * java-1_8_0-ibm-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (ppc64le s390x x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (nosrc ppc64le x86_64) * java-1_8_0-ibm-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) *java-1_8_0-ibm-devel-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (nosrc ppc64le x86_64) * java-1_8_0-ibm-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (nosrc ppc64le x86_64) * java-1_8_0-ibm-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.55-150000.3.109.1 * SUSE Enterprise Storage 7.1 (nosrc x86_64) * java-1_8_0-ibm-1.8.0_sr8.55-150000.3.109.1 * SUSE Enterprise Storage 7.1 (x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-plugin-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.55-150000.3.109.1 * openSUSE Leap 15.6 (nosrc ppc64le s390x x86_64) * java-1_8_0-ibm-1.8.0_sr8.55-150000.3.109.1 * openSUSE Leap 15.6 (x86_64) * java-1_8_0-ibm-devel-32bit-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-plugin-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-32bit-1.8.0_sr8.55-150000.3.109.1 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * java-1_8_0-ibm-src-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-demo-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-devel-1.8.0_sr8.55-150000.3.109.1 * Legacy Module 15-SP6 (nosrc ppc64le s390xx86_64) * java-1_8_0-ibm-1.8.0_sr8.55-150000.3.109.1 * Legacy Module 15-SP6 (ppc64le s390x x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.55-150000.3.109.1 * Legacy Module 15-SP6 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.55-150000.3.109.1 * Legacy Module 15-SP7 (nosrc ppc64le s390x x86_64) * java-1_8_0-ibm-1.8.0_sr8.55-150000.3.109.1 * Legacy Module 15-SP7 (ppc64le s390x x86_64) * java-1_8_0-ibm-src-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-demo-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-devel-1.8.0_sr8.55-150000.3.109.1 * Legacy Module 15-SP7 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (nosrc x86_64) * java-1_8_0-ibm-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-plugin-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (nosrc x86_64) * java-1_8_0-ibm-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-plugin-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (nosrc x86_64) * java-1_8_0-ibm-1.8.0_sr8.55-150000.3.109.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-plugin-1.8.0_sr8.55-150000.3.109.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.55-150000.3.109.1 ## References: * https://www.suse.com/security/cve/CVE-2025-53057.html * https://www.suse.com/security/cve/CVE-2025-53066.html *https://www.suse.com/security/cve/CVE-2025-61748.html * https://bugzilla.suse.com/show_bug.cgi?id=1252414 * https://bugzilla.suse.com/show_bug.cgi?id=1252417 * https://bugzilla.suse.com/show_bug.cgi?id=1252418 * https://bugzilla.suse.com/show_bug.cgi?id=1252758 . An openSUSE update for java-1_8_0-ibm fixes three important vulnerabilities, ensuring better security.. openSUSE java security update important vulnerabilities. . Severity: Important. LinuxSecurity.com Team
* bsc#1246806 * bsc#1252414 * bsc#1252417 * bsc#1252418 . # Security update for java-21-openjdk Announcement ID: SUSE-SU-2025:3859-1 Release Date: 2025-10-29T15:10:42Z Rating: important References: * bsc#1246806 * bsc#1252414 * bsc#1252417 * bsc#1252418 Cross-References: * CVE-2025-53057 * CVE-2025-53066 * CVE-2025-61748 CVSS scores: * CVE-2025-53057 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-53057 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53057 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-53066 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-53066 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-53066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-61748 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-61748 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-61748 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities and has one security fix can now be installed. ## Description: This update for java-21-openjdk fixes the following issues: Update to upstream tag jdk-21.0.9+10 (October 2025 CPU): * CVE-2025-53057: Fixed unauthenticated attacker can achieve unauthorized creation, deletion or modification access to critical data (bsc#1252414). * CVE-2025-53066: Fixedunauthenticated attacker can achive unauthorized access to critical data or complete access (bsc#1252417). * CVE-2025-61748: Fixed unauthenticated attacker can achive unauthorized update, insert or delete access to some resources (bsc#1252418). Other bug fixes: * Do not embed rebuild counter (bsc#1246806) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-3859=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-3859=1 openSUSE-SLE-15.6-2025-3859=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-3859=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-21-openjdk-headless-debuginfo-21.0.9.0-150600.3.18.2 * java-21-openjdk-demo-21.0.9.0-150600.3.18.2 * java-21-openjdk-debuginfo-21.0.9.0-150600.3.18.2 * java-21-openjdk-devel-debuginfo-21.0.9.0-150600.3.18.2 * java-21-openjdk-21.0.9.0-150600.3.18.2 * java-21-openjdk-headless-21.0.9.0-150600.3.18.2 * java-21-openjdk-debugsource-21.0.9.0-150600.3.18.2 * java-21-openjdk-devel-21.0.9.0-150600.3.18.2 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * java-21-openjdk-headless-debuginfo-21.0.9.0-150600.3.18.2 * java-21-openjdk-demo-21.0.9.0-150600.3.18.2 * java-21-openjdk-debuginfo-21.0.9.0-150600.3.18.2 * java-21-openjdk-src-21.0.9.0-150600.3.18.2 * java-21-openjdk-devel-debuginfo-21.0.9.0-150600.3.18.2 * java-21-openjdk-21.0.9.0-150600.3.18.2 * java-21-openjdk-headless-21.0.9.0-150600.3.18.2 * java-21-openjdk-jmods-21.0.9.0-150600.3.18.2 * java-21-openjdk-debugsource-21.0.9.0-150600.3.18.2 * java-21-openjdk-devel-21.0.9.0-150600.3.18.2 * openSUSE Leap 15.6 (noarch) * java-21-openjdk-javadoc-21.0.9.0-150600.3.18.2 * Basesystem Module15-SP6 (aarch64 ppc64le s390x x86_64) * java-21-openjdk-headless-debuginfo-21.0.9.0-150600.3.18.2 * java-21-openjdk-demo-21.0.9.0-150600.3.18.2 * java-21-openjdk-debuginfo-21.0.9.0-150600.3.18.2 * java-21-openjdk-devel-debuginfo-21.0.9.0-150600.3.18.2 * java-21-openjdk-21.0.9.0-150600.3.18.2 * java-21-openjdk-headless-21.0.9.0-150600.3.18.2 * java-21-openjdk-debugsource-21.0.9.0-150600.3.18.2 * java-21-openjdk-devel-21.0.9.0-150600.3.18.2 ## References: * https://www.suse.com/security/cve/CVE-2025-53057.html * https://www.suse.com/security/cve/CVE-2025-53066.html * https://www.suse.com/security/cve/CVE-2025-61748.html * https://bugzilla.suse.com/show_bug.cgi?id=1246806 * https://bugzilla.suse.com/show_bug.cgi?id=1252414 * https://bugzilla.suse.com/show_bug.cgi?id=1252417 * https://bugzilla.suse.com/show_bug.cgi?id=1252418 . This update for java-21-openjdk addresses critical issues and enhances data protection in SUSE systems.. SUSE Java Update, OpenJDK Security, Important Patch for Java, SUSE Security Fix. . Severity: Important. LinuxSecurity.com Team
An update that solves five vulnerabilities can now be installed. . # Security update for mariadb Announcement ID: SUSE-SU-2025:03275-1 Release Date: 2025-09-19T12:16:20Z Rating: moderate References: * bsc#1239150 * bsc#1239151 * bsc#1249212 * bsc#1249213 * bsc#1249219 Cross-References: * CVE-2023-52969 * CVE-2023-52970 * CVE-2023-52971 * CVE-2025-30693 * CVE-2025-30722 CVSS scores: * CVE-2023-52969 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52969 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52970 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52970 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52971 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52971 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2025-30693 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2025-30693 ( NVD ): 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2025-30722 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-30722 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * Galera for Ericsson 15 SP6 * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves five vulnerabilities can now be installed. ## Description: This update for mariadb fixes the following issues: Update to version 10.11.14. Security issues fixed: * CVE-2025-30693: InnoDB issue allows high privileged attacker with network access to gain unauthorized update, insert or delete access to data and cause repeatable crash in MySQL server (bsc#1249213). * CVE-2025-30722:mysqldump issue allows low privileged attacker with network access to gain unauthorized update, insert or delete access to data in MySQL Client (bsc#1249212). * CVE-2023-52969: crash with empty backtrace log in MariaDB Server (bsc#1239150). * CVE-2023-52970: crash in MariaDB Server when inserting from derived table containing insert target table (bsc#1239151). * CVE-2023-52971: crash in the optimizer of MariaDB Server when processing certain queries with subqueries (bsc#1249219). Release notes and changelog: * https://mariadb.com/docs/release-notes/community-server/10.11/10.11.14 * https://mariadb.com/docs/release-notes/community-server/changelogs/10.11/10.11.14 * https://mariadb.com/docs/release-notes/community-server/10.11/10.11.13 * https://mariadb.com/docs/release-notes/community-server/changelogs/10.11/10.11.13 * https://mariadb.com/docs/release-notes/community-server/10.11/10.11.12 * https://mariadb.com/docs/release-notes/community-server/changelogs/10.11/10.11.12 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-3275=1 SUSE-2025-3275=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-3275=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2025-3275=1 * Galera for Ericsson 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-ERICSSON-2025-3275=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * mariadb-test-debuginfo-10.11.14-150600.4.14.1 * libmariadbd19-debuginfo-10.11.14-150600.4.14.1 * mariadb-debuginfo-10.11.14-150600.4.14.1 * mariadb-rpm-macros-10.11.14-150600.4.14.1 * mariadb-bench-debuginfo-10.11.14-150600.4.14.1 * mariadb-bench-10.11.14-150600.4.14.1 * mariadb-test-10.11.14-150600.4.14.1 * libmariadbd19-10.11.14-150600.4.14.1 * libmariadbd-devel-10.11.14-150600.4.14.1 * mariadb-client-debuginfo-10.11.14-150600.4.14.1 * mariadb-debugsource-10.11.14-150600.4.14.1 * mariadb-galera-10.11.14-150600.4.14.1 * mariadb-client-10.11.14-150600.4.14.1 * mariadb-10.11.14-150600.4.14.1 * mariadb-tools-10.11.14-150600.4.14.1 * mariadb-tools-debuginfo-10.11.14-150600.4.14.1 * openSUSE Leap 15.6 (noarch) * mariadb-errormessages-10.11.14-150600.4.14.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * mariadb-debuginfo-10.11.14-150600.4.14.1 * mariadb-debugsource-10.11.14-150600.4.14.1 * mariadb-galera-10.11.14-150600.4.14.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libmariadbd19-debuginfo-10.11.14-150600.4.14.1 * mariadb-debuginfo-10.11.14-150600.4.14.1 * libmariadbd19-10.11.14-150600.4.14.1 * libmariadbd-devel-10.11.14-150600.4.14.1 * mariadb-client-debuginfo-10.11.14-150600.4.14.1 * mariadb-debugsource-10.11.14-150600.4.14.1 * mariadb-client-10.11.14-150600.4.14.1 * mariadb-10.11.14-150600.4.14.1 * mariadb-tools-10.11.14-150600.4.14.1 * mariadb-tools-debuginfo-10.11.14-150600.4.14.1 * Server Applications Module 15-SP6 (noarch) * mariadb-errormessages-10.11.14-150600.4.14.1 * Galera for Ericsson 15 SP6 (x86_64) * mariadb-debuginfo-10.11.14-150600.4.14.1 * mariadb-debugsource-10.11.14-150600.4.14.1 * mariadb-galera-10.11.14-150600.4.14.1 ## References: * https://www.suse.com/security/cve/CVE-2023-52969.html * https://www.suse.com/security/cve/CVE-2023-52970.html * https://www.suse.com/security/cve/CVE-2023-52971.html * https://www.suse.com/security/cve/CVE-2025-30693.html * https://www.suse.com/security/cve/CVE-2025-30722.html * https://bugzilla.suse.com/show_bug.cgi?id=1239150 *https://bugzilla.suse.com/show_bug.cgi?id=1239151 * https://bugzilla.suse.com/show_bug.cgi?id=1249212 * https://bugzilla.suse.com/show_bug.cgi?id=1249213 * https://bugzilla.suse.com/show_bug.cgi?id=1249219 . Important patch for openSUSE addresses several moderate issues in mariadb related to data processing. Users should act promptly.. openSUSE updates, mariadb security, moderate update, vulnerability patch, system integrity. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.