FlawAtlas
Search the atlas
OPENSUSE-SU-2026:20943-1 Not scored

Security update for java-17-openj9

This update for java-17-openj9 fixes the following issues: Changes in java-17-openj9: - Make post scripts less noisy (bsc#1267355) - Use libalternatives instead of update-alternatives for distributions where libalternatives is available - Update to OpenJDK 17.0.19 with OpenJ9 0.59.0 virtual machine - Including Oracle April 2026 CPU changes * CVE-2026-22007 (bsc#1262490), CVE-2026-22013 (bsc#1262494), CVE-2026-22016 (bsc#1262495), CVE-2026-22018 (bsc#1262496), CVE-2026-22021 (bsc#1262497), CVE-2026-23865 (bsc#1259118), CVE-2026-34268 (bsc#1262500), CVE-2026-34282 (bsc#1262501) - OpenJ9 specific security fix * CVE-2026-1188 (bsc#1265261) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.59/ - Update to OpenJDK 17.0.18 with OpenJ9 0.57.0 virtual machine - Including Oracle January 2026 CPU changes * CVE-2026-21925 (bsc#1257034), CVE-2026-21932 (bsc#1257036), CVE-2026-21933 (bsc#1257037), CVE-2026-21945 (bsc#1257038) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.57/ - Do not depend on update-desktop-files (jsc#PED-14507) - Update to OpenJDK 17.0.17 with OpenJ9 0.56.0 virtual machine - Including Oracle October 2025 CPU changes * CVE-2025-53057 (bsc#1252414), CVE-2025-53066 (bsc#1252417) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.56/ - Update to OpenJDK 17.0.16 with OpenJ9 0.53.0 virtual machine - Including Oracle July 2025 CPU changes * CVE-2025-30749 (bsc#1246595), CVE-2025-30754 (bsc#1246598), CVE-2025-50059 (bsc#1246575), CVE-2025-50106 (bsc#1246584) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.53/ - Enable bootcycle build - Do not embed rebuild counter (bsc#1246806) - Add -std=gnu99 to CFLAGS to fix gcc15 compile time error. Since the C++ part is on -std=gnu++98, this is the closest. - Added patch: * fix-build-with-gcc15.patch + fix a typo in omr that is fatal with gcc15 - Update to OpenJDK 17.0.15 with OpenJ9 0.51.0 virtual machine - Including Oracle April 2025 CPU changes * CVE-2025-21587 (bsc#1241274), CVE-2025-30691 (bsc#1241275), CVE-2025-30698 (bsc#1241276) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.51/ - fix wrong execstack flag in libj9jit (bsc#1235844) - Update to OpenJDK 17.0.14 with OpenJ9 0.49.0 virtual machine - Including Oracle October 2024 and January 2025 CPU changes * CVE-2024-21208 (bsc#1231702), CVE-2024-21210 (bsc#1231711), CVE-2024-21217 (bsc#1231716), CVE-2024-21235 (bsc#1231719), CVE-2025-21502 (bsc#1236278) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.49/

Exploit probability Not scored
Published June 11, 2026
Required by Not available
Last source change June 13, 2026

02 / AFFECTED SOFTWARE

Affected packages

openSUSE:Leap 16.0 java-17-openj9

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2026:20943-1

This update for java-17-openj9 fixes the following issues: Changes in java-17-openj9: - Make post scripts less noisy (bsc#1267355) - Use libalternatives instead of update-alternatives for distributions where libalternatives is available - Update to OpenJDK 17.0.19 with OpenJ9 0.59.0 virtual machine - Including Oracle April 2026 CPU changes * CVE-2026-22007 (bsc#1262490), CVE-2026-22013 (bsc#1262494), CVE-2026-22016 (bsc#1262495), CVE-2026-22018 (bsc#1262496), CVE-2026-22021 (bsc#1262497), CVE-2026-23865 (bsc#1259118), CVE-2026-34268 (bsc#1262500), CVE-2026-34282 (bsc#1262501) - OpenJ9 specific security fix * CVE-2026-1188 (bsc#1265261) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.59/ - Update to OpenJDK 17.0.18 with OpenJ9 0.57.0 virtual machine - Including Oracle January 2026 CPU changes * CVE-2026-21925 (bsc#1257034), CVE-2026-21932 (bsc#1257036), CVE-2026-21933 (bsc#1257037), CVE-2026-21945 (bsc#1257038) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.57/ - Do not depend on update-desktop-files (jsc#PED-14507) - Update to OpenJDK 17.0.17 with OpenJ9 0.56.0 virtual machine - Including Oracle October 2025 CPU changes * CVE-2025-53057 (bsc#1252414), CVE-2025-53066 (bsc#1252417) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.56/ - Update to OpenJDK 17.0.16 with OpenJ9 0.53.0 virtual machine - Including Oracle July 2025 CPU changes * CVE-2025-30749 (bsc#1246595), CVE-2025-30754 (bsc#1246598), CVE-2025-50059 (bsc#1246575), CVE-2025-50106 (bsc#1246584) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.53/ - Enable bootcycle build - Do not embed rebuild counter (bsc#1246806) - Add -std=gnu99 to CFLAGS to fix gcc15 compile time error. Since the C++ part is on -std=gnu++98, this is the closest. - Added patch: * fix-build-with-gcc15.patch + fix a typo in omr that is fatal with gcc15 - Update to OpenJDK 17.0.15 with OpenJ9 0.51.0 virtual machine - Including Oracle April 2025 CPU changes * CVE-2025-21587 (bsc#1241274), CVE-2025-30691 (bsc#1241275), CVE-2025-30698 (bsc#1241276) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.51/ - fix wrong execstack flag in libj9jit (bsc#1235844) - Update to OpenJDK 17.0.14 with OpenJ9 0.49.0 virtual machine - Including Oracle October 2024 and January 2025 CPU changes * CVE-2024-21208 (bsc#1231702), CVE-2024-21210 (bsc#1231711), CVE-2024-21217 (bsc#1231716), CVE-2024-21235 (bsc#1231719), CVE-2025-21502 (bsc#1236278) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.49/

View original source

05 / REFERENCES

Further evidence