USN-7884-1

    Dashboard / Vulnerabilities / USN-7884-1

    USN-7884-1

    Published: 24 Nov 2025Last Modified: 27 Apr 2026

    Summary: openjdk-25 vulnerabilities

    Details: Jinfeng Guo discovered that the Security component of OpenJDK 25 did not correctly handle certain representations of encoded strings. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. (CVE-2025-53057) Darius Bohni discovered that the JAXP component of OpenJDK 25 was vulnerable to a XML External Entity (XEE) attack. An unauthenticated remote attacker could possibly use this issue to modify files or leak sensitive information. (CVE-2025-53066) Yakov Shafranovich discovered that the Libraries component of OpenJDK 21 contained an issue where certain Strings built with StringBuilder returned an incorrect result for String.equals() checks. An unauthenticated remote attacker could possibly use this issue to update, insert, or delete accessible data. (CVE-2025-61748) In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://openjdk.org/groups/vulnerability/advisories/2025-10-21

    Affected packages

    Package

    Name: openjdk-25

    Purl: pkg:deb/ubuntu/[email protected]+8-1~22.04?arch=source&distro=jammy

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -25.0.1+8-1~22.04

    Affected versions

    25+36-1~22.04.2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    USN-7884-1 | CVE-DB