FlawAtlas
Search the atlas
SUSE-SU-2026:0415-1 Not scored

Security update for java-17-openjdk

This update for java-17-openjdk fixes the following issues: Upgrade to upstream tag jdk-17.0.18+8 (January 2026 CPU) Security fixes: - CVE-2026-21925: Fixed Oracle Java SE component RMI (bsc#1257034). - CVE-2026-21932: Fixed Oracle Java SE component AWT and JavaFX (bsc#1257036). - CVE-2026-21933: Fixed Oracle Java SE component Networking (bsc#1257037). - CVE-2026-21945: Fixed Oracle Java SE component Security (bsc#1257038). Other fixes: - OpenJDK rendering blue borders when it should not, due to missing the fix for JDK-6304250 from upstream (bsc#1255446). - Do not depend on update-desktop-files (jsc#PED-14507, jsc#PED-15216).

Exploit probability Not scored
Published February 10, 2026
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS java-17-openjdk
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS java-17-openjdk
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS java-17-openjdk
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS java-17-openjdk
SUSE:Linux Enterprise Module for Legacy 15 SP7 java-17-openjdk
SUSE:Linux Enterprise Server 15 SP4-LTSS java-17-openjdk
SUSE:Linux Enterprise Server 15 SP5-LTSS java-17-openjdk
SUSE:Linux Enterprise Server 15 SP6-LTSS java-17-openjdk
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 java-17-openjdk
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 java-17-openjdk
SUSE:Linux Enterprise Server for SAP Applications 15 SP6 java-17-openjdk
openSUSE:Leap 15.6 java-17-openjdk

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:0415-1

This update for java-17-openjdk fixes the following issues: Upgrade to upstream tag jdk-17.0.18+8 (January 2026 CPU) Security fixes: - CVE-2026-21925: Fixed Oracle Java SE component RMI (bsc#1257034). - CVE-2026-21932: Fixed Oracle Java SE component AWT and JavaFX (bsc#1257036). - CVE-2026-21933: Fixed Oracle Java SE component Networking (bsc#1257037). - CVE-2026-21945: Fixed Oracle Java SE component Security (bsc#1257038). Other fixes: - OpenJDK rendering blue borders when it should not, due to missing the fix for JDK-6304250 from upstream (bsc#1255446). - Do not depend on update-desktop-files (jsc#PED-14507, jsc#PED-15216).

View original source

05 / REFERENCES

Further evidence