An update that solves eight vulnerabilities and contains one feature can now be installed.. # Security update for java-21-openjdk Announcement ID: SUSE-SU-2026:21551-1 Release Date: 2026-05-05T15:10:02Z Rating: important References: * bsc#1259118 * bsc#1262490 * bsc#1262494 * bsc#1262495 * bsc#1262496 * bsc#1262497 * bsc#1262500 * bsc#1262501 * jsc#PED-15898 Cross-References: * CVE-2026-22007 * CVE-2026-22013 * CVE-2026-22016 * CVE-2026-22018 * CVE-2026-22021 * CVE-2026-23865 * CVE-2026-34268 * CVE-2026-34282 CVSS scores: * CVE-2026-22007 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22007 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22007 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22013 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22013 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22013 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22016 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22018 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22018 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22018 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23865 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-23865 ( SUSE ): 5.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-23865 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-34268 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34268 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34268 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34282 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34282 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34282 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities and contains one feature can now be installed. ## Description: This update for java-21-openjdk fixes the following issues: Update to upstream tag jdk-21.0.11+10 (April 2026 CPU). Security issues fixed: * CVE-2026-22007: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of accessible data (bsc#1262490). * CVE-2026-22013: JGSS: unauthenticated attacker with network access via multiple protocols can gain unauthorized access to critical data (bsc#1262494). * CVE-2026-22016: JAXP: unauthenticated attacker with network access via multiple protocols can gain unauthorized to access critical data (bsc#1262495). * CVE-2026-22018: Libraries: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1262496). * CVE-2026-22021: JSSE: unauthenticated attacker with network access via HTTPS can cause a partial denial of service (bsc#1262497). * CVE-2026-23865: freetype2: integer overflow in the `tt_var_load_item_variation_store` function allows for an out-of-bounds read when parsing HVAR/VVAR/MVAR tables in OpenType variablefonts(bsc#1259118). * CVE-2026-34268: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of data (bsc#1262500). * CVE-2026-34282: Networking: unauthenticated attacker with network access via multiple protocols can cause a hang or frequently repeatable crash (bsc#1262501). Other updates and bugfixes: * Provide the timezone-java and tzdata-java (jsc#PED-15898). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-684=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-684=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * java-21-openjdk-debuginfo-21.0.11.0-160000.1.1 * java-21-openjdk-21.0.11.0-160000.1.1 * java-21-openjdk-src-21.0.11.0-160000.1.1 * java-21-openjdk-jmods-21.0.11.0-160000.1.1 * java-21-openjdk-headless-21.0.11.0-160000.1.1 * java-21-openjdk-headless-debuginfo-21.0.11.0-160000.1.1 * java-21-openjdk-devel-21.0.11.0-160000.1.1 * java-21-openjdk-devel-debuginfo-21.0.11.0-160000.1.1 * java-21-openjdk-demo-21.0.11.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * java-21-openjdk-javadoc-21.0.11.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * java-21-openjdk-debuginfo-21.0.11.0-160000.1.1 * java-21-openjdk-21.0.11.0-160000.1.1 * java-21-openjdk-src-21.0.11.0-160000.1.1 * java-21-openjdk-jmods-21.0.11.0-160000.1.1 * java-21-openjdk-headless-21.0.11.0-160000.1.1 * java-21-openjdk-headless-debuginfo-21.0.11.0-160000.1.1 * java-21-openjdk-devel-21.0.11.0-160000.1.1 * java-21-openjdk-devel-debuginfo-21.0.11.0-160000.1.1 *java-21-openjdk-demo-21.0.11.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * java-21-openjdk-javadoc-21.0.11.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22007.html * https://www.suse.com/security/cve/CVE-2026-22013.html * https://www.suse.com/security/cve/CVE-2026-22016.html * https://www.suse.com/security/cve/CVE-2026-22018.html * https://www.suse.com/security/cve/CVE-2026-22021.html * https://www.suse.com/security/cve/CVE-2026-23865.html * https://www.suse.com/security/cve/CVE-2026-34268.html * https://www.suse.com/security/cve/CVE-2026-34282.html * https://bugzilla.suse.com/show_bug.cgi?id=1259118 * https://bugzilla.suse.com/show_bug.cgi?id=1262490 * https://bugzilla.suse.com/show_bug.cgi?id=1262494 * https://bugzilla.suse.com/show_bug.cgi?id=1262495 * https://bugzilla.suse.com/show_bug.cgi?id=1262496 * https://bugzilla.suse.com/show_bug.cgi?id=1262497 * https://bugzilla.suse.com/show_bug.cgi?id=1262500 * https://bugzilla.suse.com/show_bug.cgi?id=1262501 * https://jira.suse.com/browse/PED-15898 . An important security update for java-21-openjdk addresses eight separate vulnerabilities that need immediate action.. Java OpenJDK Update, SUSE Security Patch, Important Java Vulnerabilities. . Severity: Important. LinuxSecurity.com Team
A vulnerability has been discovered in Spreadsheet-ParseExcel, which can lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202508-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Spreadsheet-ParseExcel: Arbitrary Code Execution Date: August 06, 2025 Bugs: #920954 ID: 202508-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Spreadsheet-ParseExcel, which can lead to arbitrary code execution. Background ========== Spreadsheet::ParseExcel is a perl module to extract information from Excel files. Affected packages ================= Package Vulnerable Unaffected ------------------------------- ------------ ------------ dev-perl/Spreadsheet-ParseExcel < 0.660.0 > = 0.660.0 Description =========== A vulnerability has been discovered in Spreadsheet::ParseExcel. Please review the CVE identifier referenced below for details. Impact ====== Please review the referenced CVE identifier for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Spreadsheet::ParseExcel users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-perl/Spreadsheet-ParseExcel-0.660.0" References ========== [ 1 ] CVE-2023-7101 https://nvd.nist.gov/vuln/detail/CVE-2023-7101 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202508-05 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importanceto us. Any security concerns should be addressed to
64bit excel {im|ex}port backport fixes. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-401 2004-11-09 --------------------------------------------------------------------- Product : Fedora Core 3 Name : gnumeric Version : 1.2.13 Release : 8.fc3 Summary : A spreadsheet program for GNOME. Description : Gnumeric is a spreadsheet program for the GNOME GUI desktop environment. --------------------------------------------------------------------- Update Information: 64bit excel {im|ex}port backport fixes --------------------------------------------------------------------- * Tue Nov 02 2004 Caolan McNamara 1.2.13-8.fc3 - #rh137694# backport latex exporter fix - #rh137692# backport x64 excel fix --------------------------------------------------------------------- This update can be downloaded from: 7de9a71f78d1453aa39bcc5ebbe72fbf SRPMS/gnumeric-1.2.13-8.fc3.src.rpm 5c7cc2bb5a990372c3255b3d73835379 x86_64/gnumeric-1.2.13-8.fc3.x86_64.rpm 804d3cd619083fa319fb231a773fc444 x86_64/gnumeric-devel-1.2.13-8.fc3.x86_64.rpm 75d5e39372bd197bb978d2c519a7e32d x86_64/debug/gnumeric-debuginfo-1.2.13-8.fc3.x86_64.rpm 31b0416f67aa08d76b7414958997d767 i386/gnumeric-1.2.13-8.fc3.i386.rpm ad3e1c1297b84b45f761721ef4bda1d0 i386/gnumeric-devel-1.2.13-8.fc3.i386.rpm 78cdb4ed218a559ed59bba21bc882ebe i386/debug/gnumeric-debuginfo-1.2.13-8.fc3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- -- fedora-announce-list mailing list
A potential security problem has been fixed in the gnumeric spreadsheet package. . Red Hat, Inc. Security Advisory Package gnumeric Synopsis Potential security problem in gnumeric 0.23 Advisory ID RHSA-1999:023-01 Issue Date 1999-07-23 Keywords gnumeric security 1. Topic: A potential security problem has been fixed in the gnumeric spreadsheet package. 2. Bug IDs fixed: 3. Relevant releases/architectures: Red Hat Linux 6.0, all architectures 4. Obsoleted by: None 5. Conflicts with: None 6. RPMs required: Intel: gnumeric- 0.27-1.i386.rpm Alpha: gnumeric-0.27-1.alpha.rpm SPARC: gnumeric-0.27-1.sparc.rpm Source: gnumeric- 0.27-1.src.rpm 7. Problem description: At the request of the gnumeric maintainer a new version is being released by Red Hat which addresses potential security issues with the version of gnumeric shipped in Red Hat Linux 6.0. 8. Solution: Upgrade to the latest version listed above. 9. Verification: MD5 sum Package Name ------------------------------------------------------------------------- 41d67505f1c53ce16ea66cec874deb87 gnumeric-0.27-1.i386.rpm 89451cf299e475197350ef0367edda63 gnumeric-0.27-1.alpha.rpm c35d7f9a29fd9421ef4d5b1ac44d6b8e gnumeric-0.27-1.sparc.rpm b28c5742c32c3d69b8e6713bb7c6f789 gnumeric-0.27-1.src.rpm These packages are also PGP signed by Red Hat Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted o tampered with, examine only the md5sum with the following command: rpm --checksig --nopgp 10. References: . The Gnumeric spreadsheet tool has been patched due to a critical security vulnerability. Make sure your system is updated to enhance protection.. Gnumeric Security, Software Update, Red Hat Advisory. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.