Security update for java-21-openjdk
This update for java-21-openjdk fixes the following issues: Update to upstream tag jdk-21.0.9+10 (October 2025 CPU): - CVE-2025-53057: Fixed unauthenticated attacker can achieve unauthorized creation, deletion or modification access to critical data (bsc#1252414). - CVE-2025-53066: Fixed unauthenticated attacker can achive unauthorized access to critical data or complete access (bsc#1252417). - CVE-2025-61748: Fixed unauthenticated attacker can achive unauthorized update, insert or delete access to some resources (bsc#1252418). Other bug fixes: - Do not embed rebuild counter (bsc#1246806)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for java-21-openjdk fixes the following issues: Update to upstream tag jdk-21.0.9+10 (October 2025 CPU): - CVE-2025-53057: Fixed unauthenticated attacker can achieve unauthorized creation, deletion or modification access to critical data (bsc#1252414). - CVE-2025-53066: Fixed unauthenticated attacker can achive unauthorized access to critical data or complete access (bsc#1252417). - CVE-2025-61748: Fixed unauthenticated attacker can achive unauthorized update, insert or delete access to some resources (bsc#1252418). Other bug fixes: - Do not embed rebuild counter (bsc#1246806)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1246806
- https://bugzilla.suse.com/1252414
- https://bugzilla.suse.com/1252417
- https://bugzilla.suse.com/1252418
- https://www.suse.com/security/cve/CVE-2025-53057
- https://www.suse.com/security/cve/CVE-2025-53066
- https://www.suse.com/security/cve/CVE-2025-61748
- https://www.suse.com/support/update/announcement/2025/suse-su-20253859-1/