FlawAtlas
Search the atlas
SUSE-SU-2026:2036-1 Not scored

Security update for java-1_8_0-openj9

This update for java-1_8_0-openj9 fixes the following issues - CVE-2026-1188: eclipse: ensure room for separator in omrsysinfo_get_processor_feature_string (bsc#1265261). - CVE-2026-22007: APIs in the specified component can lead to an unauthorized read access (bsc#1262490). - CVE-2026-22013: unauthenticated attacker with network access can access to critical data (bsc#1262494). - CVE-2026-22016: APIs in the specified Component can cause unauthorized access to critical data (bsc#1262495). - CVE-2026-22018: unauthenticated attacker with network access can cause a partial denial of service (bsc#1262496). - CVE-2026-22021: APIs in the specified Component can cause a partial denial of service (bsc#1262497). - CVE-2026-23865: Integer overflow in the tt_var_load_item_variation_store function (bsc#1259118). - CVE-2026-34268: unauthenticated attacker with logon can gain unauthorized read access (bsc#1262500). Changes for java-1_8_0-openj9: - Update to OpenJDK 8u492 build 09 with OpenJ9 0.59.0 virtual machine

Exploit probability Not scored
Published May 21, 2026
Required by Not available
Last source change May 22, 2026

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:2036-1

This update for java-1_8_0-openj9 fixes the following issues - CVE-2026-1188: eclipse: ensure room for separator in omrsysinfo_get_processor_feature_string (bsc#1265261). - CVE-2026-22007: APIs in the specified component can lead to an unauthorized read access (bsc#1262490). - CVE-2026-22013: unauthenticated attacker with network access can access to critical data (bsc#1262494). - CVE-2026-22016: APIs in the specified Component can cause unauthorized access to critical data (bsc#1262495). - CVE-2026-22018: unauthenticated attacker with network access can cause a partial denial of service (bsc#1262496). - CVE-2026-22021: APIs in the specified Component can cause a partial denial of service (bsc#1262497). - CVE-2026-23865: Integer overflow in the tt_var_load_item_variation_store function (bsc#1259118). - CVE-2026-34268: unauthenticated attacker with logon can gain unauthorized read access (bsc#1262500). Changes for java-1_8_0-openj9: - Update to OpenJDK 8u492 build 09 with OpenJ9 0.59.0 virtual machine

View original source

05 / REFERENCES

Further evidence