SUSE-SU-2026:4006-1
Dashboard / Vulnerabilities / SUSE-SU-2026:4006-1
SUSE-SU-2026:4006-1
Summary: Security update for java-21-openjdk
Details: This update for java-21-openjdk fixes the following issues: Security issues fixed: - CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777). - CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778). - CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764). Non security issue fixed: - java-21-openjdk classlist depends on the CPU count of the build machine (bsc#1221224). Changes for java-21-openjdk: - Update to jdk-21.0.12.1+1 (August 2026 CSPU) + backport upcoming upgrade of timezone data (bsc#1275035) + Explicitly use G1 if the JVM supports it. GC ergonomics pick SerialGC on single-CPU machines. SerialGC does not support dumping of the shared heap, thus the classlist is different on a single-CPU builder.
References: https://www.suse.com/support/update/announcement/2026/suse-su-20264006-1/, https://bugzilla.suse.com/1221224, https://bugzilla.suse.com/1275035, https://bugzilla.suse.com/1275764, https://bugzilla.suse.com/1275777, https://bugzilla.suse.com/1275778, https://www.suse.com/security/cve/CVE-2026-60589, https://www.suse.com/security/cve/CVE-2026-61308, https://www.suse.com/security/cve/CVE-2026-70907
Affected packages
Package
Name: java-21-openjdk
Purl: pkg:rpm/suse/java-21-openjdk&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7
Affected ranges
Type: ECOSYSTEM
Events:
