SUSE-SU-2026:4054-1

    Dashboard / Vulnerabilities / SUSE-SU-2026:4054-1

    SUSE-SU-2026:4054-1

    Published: 7 Sept 2026Last Modified: 13 Sept 2026

    Summary: Security update for java-1_8_0-openjdk

    Details: This update for java-1_8_0-openjdk fixes the following issues: Update to version jdk8u504 (icedtea 3.40.1). - CVE-2026-60589: unauthenticated attacker with network access via multiple protocols can gain unauthorized read access to sensitive data (bsc#1275777). - CVE-2026-61308: unauthenticated attacker with network access via HTTP can gain unauthorized access to critical data (bsc#1275778). - CVE-2026-70907: unauthenticated attacker with network access via TLS can gain the ability to cause a partial denial of service (bsc#1275764). Changes for java-1_8_0-openjdk: - Version jdk8u504 (icedtea 3.40.1): * Import of OpenJDK 8 u504 build 01 + JDK-8382471: Improve Resource Resolving + JDK-8384708: Enhance HTTP Connections + JDK-8385390: Update FreeType to 2.14.3 + JDK-8386205: Enhance TLS server + JDK-8388811: [8u] VS2010 build broken by JDK-8374058 + JDK-8389477: Bump update version for OpenJDK: 8u504

    Affected packages

    Package

    Name: java-1_8_0-openjdk

    Purl: pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.8.0.504-27.134.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2026:4054-1 | CVE-DB