Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Red Hat Security Advisory: Java 11 OpenJDK ELS Security Update

0
High
Published: Wed Apr 22 2026 (04/22/2026, 13:51:24 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat has issued a security advisory for the java-11-openjdk packages with Extended Lifecycle Support for Red Hat Enterprise Linux 7, 8, and 9. This update addresses multiple vulnerabilities in the OpenJDK 11 runtime and development kit, including out-of-bounds reads, heap buffer overflows, use-after-free, denial of service, and information disclosure issues primarily related to the LIBPNG and GIFLIB libraries. The advisory covers 15 CVEs with high severity. No known exploits in the wild have been reported. The update is available from Red Hat, and users are advised to apply it after ensuring all previous errata are installed. Patch status is confirmed by Red Hat's advisory, indicating that fixes are available.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/26/2026, 23:19:58 UTC

Technical Analysis

This Red Hat security advisory (RHSA-2026:9254) addresses multiple high-severity vulnerabilities in the java-11-openjdk packages with Extended Lifecycle Support for RHEL 7, 8, and 9. The vulnerabilities include out-of-bounds reads (CVE-2025-66293), heap buffer overflows (CVE-2026-25646), use-after-free leading to arbitrary code execution (CVE-2026-33416), denial of service via buffer overflow (CVE-2026-26740), and information disclosure issues in LIBPNG and GIFLIB components used by OpenJDK. The advisory lists a total of 15 CVEs affecting these packages. Red Hat provides updated packages to remediate these issues and recommends applying the update after previous errata are installed. No CVSS scores are provided in the advisory, but the severity is classified as high.

Potential Impact

The vulnerabilities fixed in this update can lead to out-of-bounds memory reads, heap buffer overflows, use-after-free conditions, denial of service, information disclosure, and potentially arbitrary code execution within the Java runtime environment. These issues affect the OpenJDK 11 implementation on Red Hat Enterprise Linux versions 7, 8, and 9. Exploitation could compromise the confidentiality, integrity, and availability of affected systems running vulnerable versions of OpenJDK 11. No known exploits in the wild have been reported at the time of this advisory.

Mitigation Recommendations

Red Hat has released updated java-11-openjdk packages with Extended Lifecycle Support for RHEL 7, 8, and 9 that address these vulnerabilities. Users should apply these updates promptly after ensuring all previously released errata relevant to their systems have been installed. Detailed instructions for applying the update are available in the Red Hat advisory. Since this is an official Red Hat security advisory with fixes available, applying the vendor-provided updates is the recommended mitigation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:9254
Cve Count
15
Additional Cves
["CVE-2026-22007","CVE-2026-22013","CVE-2026-22016","CVE-2026-22018","CVE-2026-22021","CVE-2026-22695","CVE-2026-22801","CVE-2026-23865","CVE-2026-25646","CVE-2026-26740","CVE-2026-33416","CVE-2026-33636","CVE-2026-34268","CVE-2026-34282"]
Cvss Version
null

Threat ID: 6a160979e29bf47b5064583e

Added to database: 5/26/2026, 8:58:33 PM

Last enriched: 5/26/2026, 11:19:58 PM

Last updated: 5/27/2026, 4:56:12 AM

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses