Explore top 10 tips to secure your open-source projects now. Read More
×An update that solves six vulnerabilities and contains one feature can now be installed.. # Security update for erlang26 Announcement ID: SUSE-SU-2026:2010-1 Release Date: 2026-05-19T11:56:06Z Rating: important References: * bsc#1258663 * bsc#1259681 * bsc#1259682 * bsc#1259687 * bsc#1261728 * bsc#1262503 * jsc#PED-15166 Cross-References: * CVE-2026-21620 * CVE-2026-23941 * CVE-2026-23942 * CVE-2026-23943 * CVE-2026-28808 * CVE-2026-32147 CVSS scores: * CVE-2026-21620 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-21620 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-21620 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23941 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-23941 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-23941 ( NVD ): 7.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23942 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-23942 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-23942 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23943 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-23943 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23943 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-28808 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-28808 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-28808 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-28808 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32147 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-32147 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-32147 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.3 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities and contains one feature can now be installed. ## Description: This update for erlang26 fixes the following issues Security issues: * CVE-2026-21620: remote arbitrary read/write via TFTP relative path traversal (bsc#1258663). * CVE-2026-23941: HTTP Request Smuggling in Erlang OTP (bsc#1259687). * CVE-2026-23942: path traversal vulnerability in Erlang OTP (bsc#1259681). * CVE-2026-23943: denial of service due to improper handling of highly compressed data in Erlang OTP ssh (bsc#1259682). * CVE-2026-28808: incorrect authorization can lead to unauthenticatedaccess to protected CGI scripts (bsc#1261728). * CVE-2026-32147: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in SFTP chroot (bsc#1262503). Non security issue: * Fixes for FIPS mode (jsc#PED-15166. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-2010=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2010=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2010=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2010=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * erlang26-diameter-src-26.2.1-150300.7.25.1 * erlang26-et-src-26.2.1-150300.7.25.1 * erlang26-diameter-26.2.1-150300.7.25.1 * erlang26-observer-src-26.2.1-150300.7.25.1 * erlang26-debugger-src-26.2.1-150300.7.25.1 * erlang26-reltool-src-26.2.1-150300.7.25.1 * erlang26-dialyzer-debuginfo-26.2.1-150300.7.25.1 * erlang26-jinterface-src-26.2.1-150300.7.25.1 * erlang26-src-26.2.1-150300.7.25.1 * erlang26-dialyzer-26.2.1-150300.7.25.1 * erlang26-debugger-26.2.1-150300.7.25.1 * erlang26-et-26.2.1-150300.7.25.1 * erlang26-reltool-26.2.1-150300.7.25.1 * erlang26-dialyzer-src-26.2.1-150300.7.25.1 * erlang26-wx-debuginfo-26.2.1-150300.7.25.1 * erlang26-debuginfo-26.2.1-150300.7.25.1 * erlang26-debugsource-26.2.1-150300.7.25.1 * erlang26-doc-26.2.1-150300.7.25.1 * erlang26-epmd-debuginfo-26.2.1-150300.7.25.1 * erlang26-epmd-26.2.1-150300.7.25.1 * erlang26-jinterface-26.2.1-150300.7.25.1 * erlang26-26.2.1-150300.7.25.1 * erlang26-wx-26.2.1-150300.7.25.1 *erlang26-wx-src-26.2.1-150300.7.25.1 * erlang26-observer-26.2.1-150300.7.25.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * erlang26-26.2.1-150300.7.25.1 * erlang26-epmd-26.2.1-150300.7.25.1 * erlang26-debuginfo-26.2.1-150300.7.25.1 * erlang26-debugsource-26.2.1-150300.7.25.1 * erlang26-epmd-debuginfo-26.2.1-150300.7.25.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * erlang26-26.2.1-150300.7.25.1 * erlang26-epmd-26.2.1-150300.7.25.1 * erlang26-debuginfo-26.2.1-150300.7.25.1 * erlang26-debugsource-26.2.1-150300.7.25.1 * erlang26-epmd-debuginfo-26.2.1-150300.7.25.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * erlang26-26.2.1-150300.7.25.1 * erlang26-epmd-26.2.1-150300.7.25.1 * erlang26-debuginfo-26.2.1-150300.7.25.1 * erlang26-debugsource-26.2.1-150300.7.25.1 * erlang26-epmd-debuginfo-26.2.1-150300.7.25.1 ## References: * https://www.suse.com/security/cve/CVE-2026-21620.html * https://www.suse.com/security/cve/CVE-2026-23941.html * https://www.suse.com/security/cve/CVE-2026-23942.html * https://www.suse.com/security/cve/CVE-2026-23943.html * https://www.suse.com/security/cve/CVE-2026-28808.html * https://www.suse.com/security/cve/CVE-2026-32147.html * https://bugzilla.suse.com/show_bug.cgi?id=1258663 * https://bugzilla.suse.com/show_bug.cgi?id=1259681 * https://bugzilla.suse.com/show_bug.cgi?id=1259682 * https://bugzilla.suse.com/show_bug.cgi?id=1259687 * https://bugzilla.suse.com/show_bug.cgi?id=1261728 * https://bugzilla.suse.com/show_bug.cgi?id=1262503 * https://jira.suse.com/browse/PED-15166 . Update for openSUSE solves multiple vulnerabilities in erlang26 including path traversal and denial of service issues.. openSUSE erlang26 security update important vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves eight vulnerabilities and contains one feature can now be installed.. # Security update for java-17-openjdk Announcement ID: SUSE-SU-2026:21552-1 Release Date: 2026-05-05T15:12:06Z Rating: important References: * bsc#1259118 * bsc#1262490 * bsc#1262494 * bsc#1262495 * bsc#1262496 * bsc#1262497 * bsc#1262500 * bsc#1262501 * jsc#PED-15898 Cross-References: * CVE-2026-22007 * CVE-2026-22013 * CVE-2026-22016 * CVE-2026-22018 * CVE-2026-22021 * CVE-2026-23865 * CVE-2026-34268 * CVE-2026-34282 CVSS scores: * CVE-2026-22007 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22007 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22007 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22013 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22013 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22013 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22016 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22018 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22018 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22018 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23865 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-23865 ( SUSE ): 5.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-23865 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-34268 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34268 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34268 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34282 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34282 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34282 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities and contains one feature can now be installed. ## Description: This update for java-17-openjdk fixes the following issues: Upgrade to upstream tag jdk-17.0.19+10 (April 2026 CPU). Security issues fixed: * CVE-2026-22007: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of accessible data (bsc#1262490). * CVE-2026-22013: JGSS: unauthenticated attacker with network access via multiple protocols can gain unauthorized access to critical data (bsc#1262494). * CVE-2026-22016: JAXP: unauthenticated attacker with network access via multiple protocols can gain unauthorized to access critical data (bsc#1262495). * CVE-2026-22018: Libraries: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1262496). * CVE-2026-22021: JSSE: unauthenticated attacker with network access via HTTPS can cause a partial denial of service (bsc#1262497). * CVE-2026-23865: freetype2: integer overflow in the `tt_var_load_item_variation_store` function allows for an out-of-bounds read when parsing HVAR/VVAR/MVAR tables in OpenType variablefonts(bsc#1259118). * CVE-2026-34268: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of data (bsc#1262500). * CVE-2026-34282: Networking: unauthenticated attacker with network access via multiple protocols can cause a hang or frequently repeatable crash (bsc#1262501). Other updates and bugfixes: * Provide the timezone-java and tzdata-java (jsc#PED-15898). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-683=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-683=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * java-17-openjdk-jmods-17.0.19.0-160000.1.1 * java-17-openjdk-src-17.0.19.0-160000.1.1 * java-17-openjdk-demo-17.0.19.0-160000.1.1 * java-17-openjdk-devel-debuginfo-17.0.19.0-160000.1.1 * java-17-openjdk-17.0.19.0-160000.1.1 * java-17-openjdk-headless-17.0.19.0-160000.1.1 * java-17-openjdk-debuginfo-17.0.19.0-160000.1.1 * java-17-openjdk-devel-17.0.19.0-160000.1.1 * java-17-openjdk-headless-debuginfo-17.0.19.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * java-17-openjdk-javadoc-17.0.19.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * java-17-openjdk-jmods-17.0.19.0-160000.1.1 * java-17-openjdk-src-17.0.19.0-160000.1.1 * java-17-openjdk-demo-17.0.19.0-160000.1.1 * java-17-openjdk-devel-debuginfo-17.0.19.0-160000.1.1 * java-17-openjdk-17.0.19.0-160000.1.1 * java-17-openjdk-headless-17.0.19.0-160000.1.1 * java-17-openjdk-debuginfo-17.0.19.0-160000.1.1 * java-17-openjdk-devel-17.0.19.0-160000.1.1 *java-17-openjdk-headless-debuginfo-17.0.19.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * java-17-openjdk-javadoc-17.0.19.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22007.html * https://www.suse.com/security/cve/CVE-2026-22013.html * https://www.suse.com/security/cve/CVE-2026-22016.html * https://www.suse.com/security/cve/CVE-2026-22018.html * https://www.suse.com/security/cve/CVE-2026-22021.html * https://www.suse.com/security/cve/CVE-2026-23865.html * https://www.suse.com/security/cve/CVE-2026-34268.html * https://www.suse.com/security/cve/CVE-2026-34282.html * https://bugzilla.suse.com/show_bug.cgi?id=1259118 * https://bugzilla.suse.com/show_bug.cgi?id=1262490 * https://bugzilla.suse.com/show_bug.cgi?id=1262494 * https://bugzilla.suse.com/show_bug.cgi?id=1262495 * https://bugzilla.suse.com/show_bug.cgi?id=1262496 * https://bugzilla.suse.com/show_bug.cgi?id=1262497 * https://bugzilla.suse.com/show_bug.cgi?id=1262500 * https://bugzilla.suse.com/show_bug.cgi?id=1262501 * https://jira.suse.com/browse/PED-15898 . An important SUSE update for java-17-openjdk addresses eight issues, enhancing security and stability of the infrastructure.. SUSE Update, java-17-openjdk, important Security Fix, Java Security Update. . Severity: Important. LinuxSecurity.com Team
An update that solves eight vulnerabilities and contains one feature can now be installed.. # Security update for java-11-openjdk Announcement ID: SUSE-SU-2026:1731-1 Release Date: 2026-05-07T00:42:28Z Rating: important References: * bsc#1259118 * bsc#1262490 * bsc#1262494 * bsc#1262495 * bsc#1262496 * bsc#1262497 * bsc#1262500 * bsc#1262501 * jsc#PED-15898 Cross-References: * CVE-2026-22007 * CVE-2026-22013 * CVE-2026-22016 * CVE-2026-22018 * CVE-2026-22021 * CVE-2026-23865 * CVE-2026-34268 * CVE-2026-34282 CVSS scores: * CVE-2026-22007 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22007 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22007 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22013 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22013 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22013 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22016 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22018 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22018 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22018 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23865 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-23865 ( SUSE ): 5.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-23865 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-34268 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34268 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34268 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34282 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34282 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34282 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Legacy Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves eight vulnerabilities and contains one feature can now be installed. ## Description: This update for java-11-openjdk fixes the following issues: Upgrade to upstream tag jdk-11.0.31+11 (April 2026 CPU). Security issues fixed: * CVE-2026-22007: Security: unauthenticated attacker withlogon to the infrastructure where java executes can gain unauthorized read access to a subset of accessible data (bsc#1262490). * CVE-2026-22013: JGSS: unauthenticated attacker with network access via multiple protocols can gain unauthorized access to critical data (bsc#1262494). * CVE-2026-22016: JAXP: unauthenticated attacker with network access via multiple protocols can gain unauthorized to access critical data (bsc#1262495). * CVE-2026-22018: Libraries: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1262496). * CVE-2026-22021: JSSE: unauthenticated attacker with network access via HTTPS can cause a partial denial of service (bsc#1262497). * CVE-2026-23865: freetype2: integer overflow in the `tt_var_load_item_variation_store` function allows for an out-of-bounds read when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts(bsc#1259118). * CVE-2026-34268: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of data (bsc#1262500). * CVE-2026-34282: Networking: unauthenticated attacker with network access via multiple protocols can cause a hang or frequently repeatable crash (bsc#1262501). Other updates and bugfixes: * Provide the timezone-java and tzdata-java (jsc#PED-15898). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1731=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1731=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-1731=1 * SUSE Package Hub 15 15-SP7 zypper in -t patchSUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-1731=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1731=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1731=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1731=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1731=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1731=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1731=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1731=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1731=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-11-openjdk-headless-11.0.31.0-150000.3.138.1 * java-11-openjdk-demo-11.0.31.0-150000.3.138.1 * java-11-openjdk-11.0.31.0-150000.3.138.1 * java-11-openjdk-devel-11.0.31.0-150000.3.138.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * java-11-openjdk-headless-11.0.31.0-150000.3.138.1 * java-11-openjdk-demo-11.0.31.0-150000.3.138.1 * java-11-openjdk-headless-debuginfo-11.0.31.0-150000.3.138.1 * java-11-openjdk-debugsource-11.0.31.0-150000.3.138.1 * java-11-openjdk-debuginfo-11.0.31.0-150000.3.138.1 * java-11-openjdk-11.0.31.0-150000.3.138.1 * java-11-openjdk-devel-debuginfo-11.0.31.0-150000.3.138.1 * java-11-openjdk-devel-11.0.31.0-150000.3.138.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.31.0-150000.3.138.1 *java-11-openjdk-demo-11.0.31.0-150000.3.138.1 * java-11-openjdk-headless-debuginfo-11.0.31.0-150000.3.138.1 * java-11-openjdk-debugsource-11.0.31.0-150000.3.138.1 * java-11-openjdk-debuginfo-11.0.31.0-150000.3.138.1 * java-11-openjdk-11.0.31.0-150000.3.138.1 * java-11-openjdk-devel-debuginfo-11.0.31.0-150000.3.138.1 * java-11-openjdk-devel-11.0.31.0-150000.3.138.1 * SUSE Package Hub 15 15-SP7 (noarch) * java-11-openjdk-javadoc-11.0.31.0-150000.3.138.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * java-11-openjdk-headless-11.0.31.0-150000.3.138.1 * java-11-openjdk-demo-11.0.31.0-150000.3.138.1 * java-11-openjdk-debugsource-11.0.31.0-150000.3.138.1 * java-11-openjdk-11.0.31.0-150000.3.138.1 * java-11-openjdk-devel-11.0.31.0-150000.3.138.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * java-11-openjdk-headless-11.0.31.0-150000.3.138.1 * java-11-openjdk-demo-11.0.31.0-150000.3.138.1 * java-11-openjdk-debugsource-11.0.31.0-150000.3.138.1 * java-11-openjdk-11.0.31.0-150000.3.138.1 * java-11-openjdk-devel-11.0.31.0-150000.3.138.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * java-11-openjdk-headless-11.0.31.0-150000.3.138.1 * java-11-openjdk-demo-11.0.31.0-150000.3.138.1 * java-11-openjdk-11.0.31.0-150000.3.138.1 * java-11-openjdk-devel-11.0.31.0-150000.3.138.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * java-11-openjdk-headless-11.0.31.0-150000.3.138.1 * java-11-openjdk-demo-11.0.31.0-150000.3.138.1 * java-11-openjdk-11.0.31.0-150000.3.138.1 * java-11-openjdk-devel-11.0.31.0-150000.3.138.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.31.0-150000.3.138.1 * java-11-openjdk-demo-11.0.31.0-150000.3.138.1 * java-11-openjdk-debugsource-11.0.31.0-150000.3.138.1 *java-11-openjdk-11.0.31.0-150000.3.138.1 * java-11-openjdk-devel-11.0.31.0-150000.3.138.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.31.0-150000.3.138.1 * java-11-openjdk-demo-11.0.31.0-150000.3.138.1 * java-11-openjdk-11.0.31.0-150000.3.138.1 * java-11-openjdk-devel-11.0.31.0-150000.3.138.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.31.0-150000.3.138.1 * java-11-openjdk-demo-11.0.31.0-150000.3.138.1 * java-11-openjdk-headless-debuginfo-11.0.31.0-150000.3.138.1 * java-11-openjdk-debugsource-11.0.31.0-150000.3.138.1 * java-11-openjdk-debuginfo-11.0.31.0-150000.3.138.1 * java-11-openjdk-11.0.31.0-150000.3.138.1 * java-11-openjdk-devel-debuginfo-11.0.31.0-150000.3.138.1 * java-11-openjdk-devel-11.0.31.0-150000.3.138.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-11-openjdk-headless-11.0.31.0-150000.3.138.1 * java-11-openjdk-demo-11.0.31.0-150000.3.138.1 * java-11-openjdk-debugsource-11.0.31.0-150000.3.138.1 * java-11-openjdk-11.0.31.0-150000.3.138.1 * java-11-openjdk-devel-11.0.31.0-150000.3.138.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22007.html * https://www.suse.com/security/cve/CVE-2026-22013.html * https://www.suse.com/security/cve/CVE-2026-22016.html * https://www.suse.com/security/cve/CVE-2026-22018.html * https://www.suse.com/security/cve/CVE-2026-22021.html * https://www.suse.com/security/cve/CVE-2026-23865.html * https://www.suse.com/security/cve/CVE-2026-34268.html * https://www.suse.com/security/cve/CVE-2026-34282.html * https://bugzilla.suse.com/show_bug.cgi?id=1259118 * https://bugzilla.suse.com/show_bug.cgi?id=1262490 * https://bugzilla.suse.com/show_bug.cgi?id=1262494 * https://bugzilla.suse.com/show_bug.cgi?id=1262495 * https://bugzilla.suse.com/show_bug.cgi?id=1262496 *https://bugzilla.suse.com/show_bug.cgi?id=1262497 * https://bugzilla.suse.com/show_bug.cgi?id=1262500 * https://bugzilla.suse.com/show_bug.cgi?id=1262501 * https://jira.suse.com/browse/PED-15898 . Update for java-11-openjdk addresses eight vulnerabilities including security risks for SUSE users. Critical updates recommended.. SUSE Security Update, java-11-openjdk Fixes, Linux Security Patch. . Severity: Important. LinuxSecurity.com Team
An update that solves eight vulnerabilities and contains one feature can now be installed.. # Security update for java-17-openjdk Announcement ID: SUSE-SU-2026:1732-1 Release Date: 2026-05-07T00:43:53Z Rating: important References: * bsc#1259118 * bsc#1262490 * bsc#1262494 * bsc#1262495 * bsc#1262496 * bsc#1262497 * bsc#1262500 * bsc#1262501 * jsc#PED-15898 Cross-References: * CVE-2026-22007 * CVE-2026-22013 * CVE-2026-22016 * CVE-2026-22018 * CVE-2026-22021 * CVE-2026-23865 * CVE-2026-34268 * CVE-2026-34282 CVSS scores: * CVE-2026-22007 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22007 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22007 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22013 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22013 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22013 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22016 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22018 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22018 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22018 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23865 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-23865 ( SUSE ): 5.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-23865 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-34268 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34268 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34268 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34282 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34282 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34282 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Legacy Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities and contains one feature can now be installed. ## Description: This update for java-17-openjdk fixes the following issues: Upgrade to upstream tag jdk-17.0.19+10 (April 2026 CPU). Security issues fixed: * CVE-2026-22007: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of accessible data (bsc#1262490). * CVE-2026-22013: JGSS: unauthenticated attacker with network access via multiple protocols can gain unauthorized access to critical data (bsc#1262494). * CVE-2026-22016: JAXP: unauthenticated attacker with network access via multiple protocols can gain unauthorized to access critical data (bsc#1262495). * CVE-2026-22018: Libraries: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1262496). * CVE-2026-22021: JSSE: unauthenticated attacker with network access via HTTPS can cause a partial denial of service (bsc#1262497). * CVE-2026-23865: freetype2: integer overflow in the `tt_var_load_item_variation_store` function allows for an out-of-bounds read when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts(bsc#1259118). * CVE-2026-34268: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of data (bsc#1262500). * CVE-2026-34282: Networking: unauthenticated attacker with network access via multiple protocols can cause a hang or frequently repeatable crash (bsc#1262501). Other updates and bugfixes: * Provide the timezone-java and tzdata-java (jsc#PED-15898). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1732=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-1732=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1732=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1732=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypperin -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1732=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1732=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1732=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1732=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1732=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1732=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1732=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1732=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-src-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-jmods-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * openSUSE Leap 15.4 (noarch) * java-17-openjdk-javadoc-17.0.19.0-150400.3.66.2 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 *java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 *java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * java-17-openjdk-debugsource-17.0.19.0-150400.3.66.2 * java-17-openjdk-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-debuginfo-17.0.19.0-150400.3.66.2 * java-17-openjdk-devel-17.0.19.0-150400.3.66.2 * java-17-openjdk-17.0.19.0-150400.3.66.2 * java-17-openjdk-demo-17.0.19.0-150400.3.66.2 * java-17-openjdk-headless-17.0.19.0-150400.3.66.2 ## References: * https://www.suse.com/security/cve/CVE-2026-22007.html * https://www.suse.com/security/cve/CVE-2026-22013.html * https://www.suse.com/security/cve/CVE-2026-22016.html * https://www.suse.com/security/cve/CVE-2026-22018.html * https://www.suse.com/security/cve/CVE-2026-22021.html * https://www.suse.com/security/cve/CVE-2026-23865.html * https://www.suse.com/security/cve/CVE-2026-34268.html * https://www.suse.com/security/cve/CVE-2026-34282.html * https://bugzilla.suse.com/show_bug.cgi?id=1259118 * https://bugzilla.suse.com/show_bug.cgi?id=1262490 * https://bugzilla.suse.com/show_bug.cgi?id=1262494 * https://bugzilla.suse.com/show_bug.cgi?id=1262495 *https://bugzilla.suse.com/show_bug.cgi?id=1262496 * https://bugzilla.suse.com/show_bug.cgi?id=1262497 * https://bugzilla.suse.com/show_bug.cgi?id=1262500 * https://bugzilla.suse.com/show_bug.cgi?id=1262501 * https://jira.suse.com/browse/PED-15898 . Fixes eight security issues and one feature update for java-17-openjdk on SUSE. Critical updates recommended.. java security patch, SUSE update, openjdk vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves eight vulnerabilities and contains one feature can now be installed.. # Security update for java-11-openjdk Announcement ID: SUSE-SU-2026:1703-1 Release Date: 2026-05-06T08:45:05Z Rating: important References: * bsc#1259118 * bsc#1262490 * bsc#1262494 * bsc#1262495 * bsc#1262496 * bsc#1262497 * bsc#1262500 * bsc#1262501 * jsc#PED-15898 Cross-References: * CVE-2026-22007 * CVE-2026-22013 * CVE-2026-22016 * CVE-2026-22018 * CVE-2026-22021 * CVE-2026-23865 * CVE-2026-34268 * CVE-2026-34282 CVSS scores: * CVE-2026-22007 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22007 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22007 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22013 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22013 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22013 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22016 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22018 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22018 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22018 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23865 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-23865 ( SUSE ): 5.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-23865 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-34268 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34268 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34268 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34282 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34282 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34282 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves eight vulnerabilities and contains one feature can now be installed. ## Description: This update for java-11-openjdk fixes the following issues: Upgrade to upstream tag jdk-11.0.31+11 (April 2026 CPU). Security issues fixed: * CVE-2026-22007: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of accessible data (bsc#1262490). * CVE-2026-22013: JGSS: unauthenticated attacker with network access via multiple protocols can gain unauthorized access to critical data (bsc#1262494). * CVE-2026-22016: JAXP: unauthenticated attacker with network access via multiple protocols can gain unauthorized to access critical data (bsc#1262495). * CVE-2026-22018: Libraries: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1262496). * CVE-2026-22021: JSSE: unauthenticated attacker with network access via HTTPS can cause a partial denial of service (bsc#1262497). * CVE-2026-23865: freetype2: integeroverflow in the `tt_var_load_item_variation_store` function allows for an out-of-bounds read when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts(bsc#1259118). * CVE-2026-34268: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of data (bsc#1262500). * CVE-2026-34282: Networking: unauthenticated attacker with network access via multiple protocols can cause a hang or frequently repeatable crash (bsc#1262501). Other updates and bugfixes: * Provide the timezone-java and tzdata-java (jsc#PED-15898). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-1703=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-1703=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-headless-11.0.31.0-3.99.1 * java-11-openjdk-debuginfo-11.0.31.0-3.99.1 * java-11-openjdk-11.0.31.0-3.99.1 * java-11-openjdk-demo-11.0.31.0-3.99.1 * java-11-openjdk-devel-11.0.31.0-3.99.1 * java-11-openjdk-debugsource-11.0.31.0-3.99.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * java-11-openjdk-headless-11.0.31.0-3.99.1 * java-11-openjdk-debuginfo-11.0.31.0-3.99.1 * java-11-openjdk-11.0.31.0-3.99.1 * java-11-openjdk-demo-11.0.31.0-3.99.1 * java-11-openjdk-devel-11.0.31.0-3.99.1 * java-11-openjdk-debugsource-11.0.31.0-3.99.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22007.html * https://www.suse.com/security/cve/CVE-2026-22013.html * https://www.suse.com/security/cve/CVE-2026-22016.html *https://www.suse.com/security/cve/CVE-2026-22018.html * https://www.suse.com/security/cve/CVE-2026-22021.html * https://www.suse.com/security/cve/CVE-2026-23865.html * https://www.suse.com/security/cve/CVE-2026-34268.html * https://www.suse.com/security/cve/CVE-2026-34282.html * https://bugzilla.suse.com/show_bug.cgi?id=1259118 * https://bugzilla.suse.com/show_bug.cgi?id=1262490 * https://bugzilla.suse.com/show_bug.cgi?id=1262494 * https://bugzilla.suse.com/show_bug.cgi?id=1262495 * https://bugzilla.suse.com/show_bug.cgi?id=1262496 * https://bugzilla.suse.com/show_bug.cgi?id=1262497 * https://bugzilla.suse.com/show_bug.cgi?id=1262500 * https://bugzilla.suse.com/show_bug.cgi?id=1262501 * https://jira.suse.com/browse/PED-15898 . Update for java-11-openjdk resolves eight issues and enhances security against unauthorized access on SUSE.. SUSE Security, java-11-openjdk, network vulnerability, update patch, SUSE Linux recommendation. . Severity: Important. LinuxSecurity.com Team
An update that solves eight vulnerabilities and contains one feature can now be installed.. # Security update for java-21-openjdk Announcement ID: SUSE-SU-2026:1705-1 Release Date: 2026-05-06T10:28:39Z Rating: important References: * bsc#1259118 * bsc#1262490 * bsc#1262494 * bsc#1262495 * bsc#1262496 * bsc#1262497 * bsc#1262500 * bsc#1262501 * jsc#PED-15898 Cross-References: * CVE-2026-22007 * CVE-2026-22013 * CVE-2026-22016 * CVE-2026-22018 * CVE-2026-22021 * CVE-2026-23865 * CVE-2026-34268 * CVE-2026-34282 CVSS scores: * CVE-2026-22007 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22007 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22007 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22013 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22013 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22013 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22016 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22018 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22018 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22018 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23865 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-23865 ( SUSE ): 5.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-23865 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-34268 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34268 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34268 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34282 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34282 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34282 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities and contains one feature can now be installed. ## Description: This update for java-21-openjdk fixes the following issues: Update to upstream tag jdk-21.0.11+10 (April 2026 CPU). Security issues fixed: * CVE-2026-22007: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of accessible data (bsc#1262490). * CVE-2026-22013: JGSS: unauthenticated attacker with network access via multiple protocols can gain unauthorized access to critical data (bsc#1262494). * CVE-2026-22016: JAXP: unauthenticated attacker with network access via multiple protocols can gain unauthorized to access critical data (bsc#1262495). * CVE-2026-22018: Libraries: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1262496). * CVE-2026-22021: JSSE: unauthenticated attacker with networkaccess via HTTPS can cause a partial denial of service (bsc#1262497). * CVE-2026-23865: freetype2: integer overflow in the `tt_var_load_item_variation_store` function allows for an out-of-bounds read when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts(bsc#1259118). * CVE-2026-34268: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of data (bsc#1262500). * CVE-2026-34282: Networking: unauthenticated attacker with network access via multiple protocols can cause a hang or frequently repeatable crash (bsc#1262501). Other updates and bugfixes: * Provide the timezone-java and tzdata-java (jsc#PED-15898). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1705=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1705=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1705=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1705=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * java-21-openjdk-devel-21.0.11.0-150600.3.26.1 * java-21-openjdk-headless-21.0.11.0-150600.3.26.1 * java-21-openjdk-21.0.11.0-150600.3.26.1 * java-21-openjdk-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-headless-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-devel-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-debugsource-21.0.11.0-150600.3.26.1 * java-21-openjdk-demo-21.0.11.0-150600.3.26.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * java-21-openjdk-devel-21.0.11.0-150600.3.26.1 *java-21-openjdk-headless-21.0.11.0-150600.3.26.1 * java-21-openjdk-21.0.11.0-150600.3.26.1 * java-21-openjdk-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-headless-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-devel-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-debugsource-21.0.11.0-150600.3.26.1 * java-21-openjdk-demo-21.0.11.0-150600.3.26.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * java-21-openjdk-devel-21.0.11.0-150600.3.26.1 * java-21-openjdk-jmods-21.0.11.0-150600.3.26.1 * java-21-openjdk-headless-21.0.11.0-150600.3.26.1 * java-21-openjdk-src-21.0.11.0-150600.3.26.1 * java-21-openjdk-21.0.11.0-150600.3.26.1 * java-21-openjdk-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-headless-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-devel-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-debugsource-21.0.11.0-150600.3.26.1 * java-21-openjdk-demo-21.0.11.0-150600.3.26.1 * openSUSE Leap 15.6 (noarch) * java-21-openjdk-javadoc-21.0.11.0-150600.3.26.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-21-openjdk-devel-21.0.11.0-150600.3.26.1 * java-21-openjdk-headless-21.0.11.0-150600.3.26.1 * java-21-openjdk-21.0.11.0-150600.3.26.1 * java-21-openjdk-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-headless-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-devel-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-debugsource-21.0.11.0-150600.3.26.1 * java-21-openjdk-demo-21.0.11.0-150600.3.26.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22007.html * https://www.suse.com/security/cve/CVE-2026-22013.html * https://www.suse.com/security/cve/CVE-2026-22016.html * https://www.suse.com/security/cve/CVE-2026-22018.html * https://www.suse.com/security/cve/CVE-2026-22021.html * https://www.suse.com/security/cve/CVE-2026-23865.html * https://www.suse.com/security/cve/CVE-2026-34268.html *https://www.suse.com/security/cve/CVE-2026-34282.html * https://bugzilla.suse.com/show_bug.cgi?id=1259118 * https://bugzilla.suse.com/show_bug.cgi?id=1262490 * https://bugzilla.suse.com/show_bug.cgi?id=1262494 * https://bugzilla.suse.com/show_bug.cgi?id=1262495 * https://bugzilla.suse.com/show_bug.cgi?id=1262496 * https://bugzilla.suse.com/show_bug.cgi?id=1262497 * https://bugzilla.suse.com/show_bug.cgi?id=1262500 * https://bugzilla.suse.com/show_bug.cgi?id=1262501 * https://jira.suse.com/browse/PED-15898 . An important security update for java-21-openjdk in openSUSE addresses eight vulnerabilities and improves safety.. openSUSE java-21-openjdk security update important vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves eight vulnerabilities and contains one feature can now be installed.. # Security update for java-21-openjdk Announcement ID: SUSE-SU-2026:1705-1 Release Date: 2026-05-06T10:28:39Z Rating: important References: * bsc#1259118 * bsc#1262490 * bsc#1262494 * bsc#1262495 * bsc#1262496 * bsc#1262497 * bsc#1262500 * bsc#1262501 * jsc#PED-15898 Cross-References: * CVE-2026-22007 * CVE-2026-22013 * CVE-2026-22016 * CVE-2026-22018 * CVE-2026-22021 * CVE-2026-23865 * CVE-2026-34268 * CVE-2026-34282 CVSS scores: * CVE-2026-22007 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22007 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22007 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-22013 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22013 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22013 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-22016 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-22016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-22018 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22018 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22018 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-23865 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-23865 ( SUSE ): 5.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-23865 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-34268 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34268 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34268 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34282 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34282 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34282 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities and contains one feature can now be installed. ## Description: This update for java-21-openjdk fixes the following issues: Update to upstream tag jdk-21.0.11+10 (April 2026 CPU). Security issues fixed: * CVE-2026-22007: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of accessible data (bsc#1262490). * CVE-2026-22013: JGSS: unauthenticated attacker with network access via multiple protocols can gain unauthorized access to critical data (bsc#1262494). * CVE-2026-22016: JAXP: unauthenticated attacker with network access via multiple protocols can gain unauthorized to access critical data (bsc#1262495). * CVE-2026-22018: Libraries: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1262496). * CVE-2026-22021: JSSE: unauthenticated attacker with networkaccess via HTTPS can cause a partial denial of service (bsc#1262497). * CVE-2026-23865: freetype2: integer overflow in the `tt_var_load_item_variation_store` function allows for an out-of-bounds read when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts(bsc#1259118). * CVE-2026-34268: Security: unauthenticated attacker with logon to the infrastructure where java executes can gain unauthorized read access to a subset of data (bsc#1262500). * CVE-2026-34282: Networking: unauthenticated attacker with network access via multiple protocols can cause a hang or frequently repeatable crash (bsc#1262501). Other updates and bugfixes: * Provide the timezone-java and tzdata-java (jsc#PED-15898). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1705=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1705=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1705=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1705=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * java-21-openjdk-devel-21.0.11.0-150600.3.26.1 * java-21-openjdk-headless-21.0.11.0-150600.3.26.1 * java-21-openjdk-21.0.11.0-150600.3.26.1 * java-21-openjdk-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-headless-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-devel-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-debugsource-21.0.11.0-150600.3.26.1 * java-21-openjdk-demo-21.0.11.0-150600.3.26.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * java-21-openjdk-devel-21.0.11.0-150600.3.26.1 *java-21-openjdk-headless-21.0.11.0-150600.3.26.1 * java-21-openjdk-21.0.11.0-150600.3.26.1 * java-21-openjdk-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-headless-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-devel-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-debugsource-21.0.11.0-150600.3.26.1 * java-21-openjdk-demo-21.0.11.0-150600.3.26.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * java-21-openjdk-devel-21.0.11.0-150600.3.26.1 * java-21-openjdk-jmods-21.0.11.0-150600.3.26.1 * java-21-openjdk-headless-21.0.11.0-150600.3.26.1 * java-21-openjdk-src-21.0.11.0-150600.3.26.1 * java-21-openjdk-21.0.11.0-150600.3.26.1 * java-21-openjdk-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-headless-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-devel-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-debugsource-21.0.11.0-150600.3.26.1 * java-21-openjdk-demo-21.0.11.0-150600.3.26.1 * openSUSE Leap 15.6 (noarch) * java-21-openjdk-javadoc-21.0.11.0-150600.3.26.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-21-openjdk-devel-21.0.11.0-150600.3.26.1 * java-21-openjdk-headless-21.0.11.0-150600.3.26.1 * java-21-openjdk-21.0.11.0-150600.3.26.1 * java-21-openjdk-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-headless-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-devel-debuginfo-21.0.11.0-150600.3.26.1 * java-21-openjdk-debugsource-21.0.11.0-150600.3.26.1 * java-21-openjdk-demo-21.0.11.0-150600.3.26.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22007.html * https://www.suse.com/security/cve/CVE-2026-22013.html * https://www.suse.com/security/cve/CVE-2026-22016.html * https://www.suse.com/security/cve/CVE-2026-22018.html * https://www.suse.com/security/cve/CVE-2026-22021.html * https://www.suse.com/security/cve/CVE-2026-23865.html * https://www.suse.com/security/cve/CVE-2026-34268.html *https://www.suse.com/security/cve/CVE-2026-34282.html * https://bugzilla.suse.com/show_bug.cgi?id=1259118 * https://bugzilla.suse.com/show_bug.cgi?id=1262490 * https://bugzilla.suse.com/show_bug.cgi?id=1262494 * https://bugzilla.suse.com/show_bug.cgi?id=1262495 * https://bugzilla.suse.com/show_bug.cgi?id=1262496 * https://bugzilla.suse.com/show_bug.cgi?id=1262497 * https://bugzilla.suse.com/show_bug.cgi?id=1262500 * https://bugzilla.suse.com/show_bug.cgi?id=1262501 * https://jira.suse.com/browse/PED-15898 . An important update for SUSE java-21-openjdk addresses eight issues. Patching recommended for security risks.. Java Update, SUSE Java Security, Open Source Updates. . Severity: Important. LinuxSecurity.com Team
Erlang ver. 26.2.5.19. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-dd4a7e240e 2026-04-16 01:08:38.333416+00:00 -------------------------------------------------------------------------------- Name : erlang Product : Fedora 42 Version : 26.2.5.19 Release : 1.fc42 URL : https://www.erlang.org Summary : General-purpose programming language and runtime environment Description : Erlang is a general-purpose programming language and runtime environment. Erlang has built-in support for concurrency, distribution and fault tolerance. Erlang is used in several large telecommunication systems from Ericsson. -------------------------------------------------------------------------------- Update Information: Erlang ver. 26.2.5.19 -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 7 2026 Peter Lemenkov - 26.2.5.19-1 - Ver. 26.2.5.19 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2456135 - CVE-2026-28810 erlang: Erlang/OTP kernel: DNS cache poisoning via predictable DNS transaction IDs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456135 [ 2 ] Bug #2456139 - CVE-2026-28808 erlang: Erlang OTP inets modules: Unauthenticated access to protected CGI scripts via incorrect authorization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456139 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-dd4a7e240e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.