Security update for java-21-openjdk
This update for java-21-openjdk fixes the following issues: Security issues fixed: - CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777). - CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778). - CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764). Non security issue fixed: - java-21-openjdk classlist depends on the CPU count of the build machine (bsc#1221224). Changes for java-21-openjdk: - Update to jdk-21.0.12.1+1 (August 2026 CSPU) + backport upcoming upgrade of timezone data (bsc#1275035) + Explicitly use G1 if the JVM supports it. GC ergonomics pick SerialGC on single-CPU machines. SerialGC does not support dumping of the shared heap, thus the classlist is different on a single-CPU builder.
AI Analysis
Technical Summary
The java-1.8.0-openjdk packages contain multiple security vulnerabilities that have been addressed in the August 2026 Critical Security Patch Update by Oracle. The vulnerabilities include CVE-2026-60589, which improves resource resolving, CVE-2026-61308, which enhances HTTP connections, and CVE-2026-70907, which enhances the TLS server. These issues affect versions of OpenJDK 8 and related Red Hat Enterprise Linux packages prior to and including version 11.0.32.10.1, among others. The vendor advisory emphasizes the importance of applying these patches promptly to mitigate potential exploitation risks.
Potential Impact
The vulnerabilities impact the security of Java runtime and development environments by addressing resource resolving, HTTP connection handling, and TLS server functionality. While the exact exploitation impact is not detailed, these areas are critical for secure application operation. No known exploits in the wild have been reported. The severity is assessed as medium based on the advisory.
Mitigation Recommendations
A security update is available from Red Hat and Oracle as part of the August 2026 Critical Security Patch Update. Users should apply the official patches promptly to affected versions to mitigate these vulnerabilities. Oracle strongly recommends remaining on actively supported versions and applying security patches without delay. No additional mitigation steps are indicated beyond applying the official fixes.
Security update for java-21-openjdk
Description
This update for java-21-openjdk fixes the following issues: Security issues fixed: - CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777). - CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778). - CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764). Non security issue fixed: - java-21-openjdk classlist depends on the CPU count of the build machine (bsc#1221224). Changes for java-21-openjdk: - Update to jdk-21.0.12.1+1 (August 2026 CSPU) + backport upcoming upgrade of timezone data (bsc#1275035) + Explicitly use G1 if the JVM supports it. GC ergonomics pick SerialGC on single-CPU machines. SerialGC does not support dumping of the shared heap, thus the classlist is different on a single-CPU builder.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The java-1.8.0-openjdk packages contain multiple security vulnerabilities that have been addressed in the August 2026 Critical Security Patch Update by Oracle. The vulnerabilities include CVE-2026-60589, which improves resource resolving, CVE-2026-61308, which enhances HTTP connections, and CVE-2026-70907, which enhances the TLS server. These issues affect versions of OpenJDK 8 and related Red Hat Enterprise Linux packages prior to and including version 11.0.32.10.1, among others. The vendor advisory emphasizes the importance of applying these patches promptly to mitigate potential exploitation risks.
Potential Impact
The vulnerabilities impact the security of Java runtime and development environments by addressing resource resolving, HTTP connection handling, and TLS server functionality. While the exact exploitation impact is not detailed, these areas are critical for secure application operation. No known exploits in the wild have been reported. The severity is assessed as medium based on the advisory.
Mitigation Recommendations
A security update is available from Red Hat and Oracle as part of the August 2026 Critical Security Patch Update. Users should apply the official patches promptly to affected versions to mitigate these vulnerabilities. Oracle strongly recommends remaining on actively supported versions and applying security patches without delay. No additional mitigation steps are indicated beyond applying the official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Nationaal Cyber Security Centrum
- Advisory Id
- NCSC-2026-0314
- Cve Count
- 5
- Additional Cves
- ["CVE-2026-61308","CVE-2026-62574","CVE-2026-70906","CVE-2026-70907"]
- State
- PUBLISHED
Threat ID: 6a85b4a3acd9273b49250764
Added to database: 08/19/2026, 13:50:27 UTC
Last enriched: 09/29/2026, 05:09:20 UTC
Last updated: 10/03/2026, 02:59:46 UTC
Views: 52
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.