SUSE-SU-2026:4002-1
Dashboard / Vulnerabilities / SUSE-SU-2026:4002-1
SUSE-SU-2026:4002-1
Summary: Security update for java-17-openjdk
Details: This update for java-17-openjdk fixes the following issues: Upgrade to upstream tag jdk-17.0.20.1+1 (August 2026 CSPU). - CVE-2026-60589: unauthenticated attacker with network access via multiple protocols can gain unauthorized read access to a subset of accessible data (bsc#1275777). - CVE-2026-61308: unauthenticated attacker with network access via HTTP can gain unauthorized access to critical data (bsc#1275778). - CVE-2026-70907: unauthenticated attacker with network access via TLS can cause a partial denial of service (bsc#1275764). Changes for java-17-openjdk: - Upgrade to upstream tag jdk-17.0.20.1+1 (August 2026 CSPU): + JDK-8389947: [17u] Remove designator `DEFAULT_PROMOTED_VERSION_PRE=ea` for release 17.0.20.1. + JDK-8333743: Change `.jcheck/conf` branches property to match valid branches + JDK-8388790: Bump update version for OpenJDK: jdk-17.0.20.1 - Backport upcoming upgrade of timezone data (bsc#1275035)
References: https://www.suse.com/support/update/announcement/2026/suse-su-20264002-1/, https://bugzilla.suse.com/1275035, https://bugzilla.suse.com/1275764, https://bugzilla.suse.com/1275777, https://bugzilla.suse.com/1275778, https://www.suse.com/security/cve/CVE-2026-60589, https://www.suse.com/security/cve/CVE-2026-61308, https://www.suse.com/security/cve/CVE-2026-70907
Affected packages
Package
Name: java-17-openjdk
Purl: pkg:rpm/suse/java-17-openjdk&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015%20SP7
Affected ranges
Type: ECOSYSTEM
Events:
