openSUSE-SU-2026:21759-1
Dashboard / Vulnerabilities / openSUSE-SU-2026:21759-1
openSUSE-SU-2026:21759-1
Summary: Security update for java-21-openjdk
Details: This update for java-21-openjdk fixes the following issues: Security issues fixed: - CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777). - CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778). - CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764). Non security issue fixed: - java-21-openjdk classlist depends on the CPU count of the build machine (bsc#1221224). Changes for java-21-openjdk: - Update to jdk-21.0.12.1+1 (August 2026 CSPU) + backport upcoming upgrade of timezone data (bsc#1275035) + Explicitly use G1 if the JVM supports it. GC ergonomics pick SerialGC on single-CPU machines. SerialGC does not support dumping of the shared heap, thus the classlist is different on a single-CPU builder.
References: , https://bugzilla.suse.com/1221224, https://bugzilla.suse.com/1275035, https://bugzilla.suse.com/1275764, https://bugzilla.suse.com/1275777, https://bugzilla.suse.com/1275778, https://www.suse.com/security/cve/CVE-2026-60589, https://www.suse.com/security/cve/CVE-2026-61308, https://www.suse.com/security/cve/CVE-2026-70907
Affected packages
Package
Name: java-21-openjdk
Purl: pkg:rpm/opensuse/java-21-openjdk&distro=openSUSE%20Leap%2016.0
Affected ranges
Type: ECOSYSTEM
Events:
