Red Hat Security Advisory: OpenJDK 21.0.12 Security Update for Portable Linux Builds
The OpenJDK 21 packages provide the OpenJDK 21 Java Runtime Environment and the OpenJDK 21 Java Software Development Kit. This release of the Red Hat build of OpenJDK 21 (21.0.12) for portable Linux serves as a replacement for the Red Hat build of OpenJDK 21 (21.0.11) and includes security and bug fixes as well as enhancements. For further information, refer to the release notes linked to in the References section. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Improve DTLS handshaking (CVE-2026-46917) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK: Enhance XBM image support (CVE-2026-47021) * JDK: Enhance Jar file processing (CVE-2026-47027) * JDK: Improve certification checking (CVE-2026-60147) * JDK: Enhance AWT ImagingLib (CVE-2026-47059) * JDK: Enhance Jar handling (CVE-2026-47063) * JDK: Update LCMS to 2.19 (CVE-2026-41254) Enhancement(s): * For the last couple of years, OpenJDK has used a single build shared among multiple RPMs and a tarball available on the customer portal. The single "portable" build has a release number ('p') and each RPM has its own release number ('r'). However, the RPM naming only showed the RPM release number, while the version output from the build showed the portable release number, making it unclear that they were different numbers. From this release onwards, a release field of the form 'p.r' is always used for RPMs and the version output shows 'p'. (OPENJDK-4890) Bug Fix(es): For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
This Red Hat security advisory covers the OpenJDK 11 ELS packages for portable Linux builds and the Eclipse Temurin build of OpenJDK 25 for Windows. The update to OpenJDK 11.0.32 addresses multiple security vulnerabilities, including CVE-2026-41254 (integer overflow in Little CMS leading to information disclosure or denial of service), CVE-2026-46968 (TLS certificate handling enhancement), CVE-2026-46917 (DTLS handshaking improvement), CVE-2026-47010 (JPEG handling enhancement), CVE-2026-47021 (XBM image support enhancement), CVE-2026-47027 and CVE-2026-47063 (Jar file processing and handling enhancements), CVE-2026-60147 (certification checking improvement), CVE-2026-47059 (AWT ImagingLib enhancement), CVE-2026-47057 (Nashorn index handling improvement), and CVE-2026-47058 (Dataview implementation enhancement). The advisory includes detailed vendor-provided patches and instructions for applying the update on Red Hat Enterprise Linux versions 7, 8, and 9. No known exploits in the wild have been reported for these vulnerabilities.
Potential Impact
The vulnerabilities addressed include potential information disclosure and denial of service via an integer overflow in the Little CMS library, as well as multiple enhancements and fixes to TLS/DTLS certificate handling, image processing, Jar file handling, and certification checking within OpenJDK. These issues could affect the security and stability of Java applications running on affected OpenJDK versions. The overall severity is rated as high by Red Hat, indicating significant security impact if unpatched.
Mitigation Recommendations
Red Hat has released official security updates for OpenJDK 11 ELS (version 11.0.32) and the Eclipse Temurin build of OpenJDK 25 (version 25.0.4) that address these vulnerabilities. Users should apply these updates promptly after ensuring all previously released errata relevant to their systems have been applied. Detailed update instructions are available in the Red Hat advisory and knowledge base articles. No additional mitigation steps are required beyond applying the official patches.
Red Hat Security Advisory: OpenJDK 21.0.12 Security Update for Portable Linux Builds
Description
The OpenJDK 21 packages provide the OpenJDK 21 Java Runtime Environment and the OpenJDK 21 Java Software Development Kit. This release of the Red Hat build of OpenJDK 21 (21.0.12) for portable Linux serves as a replacement for the Red Hat build of OpenJDK 21 (21.0.11) and includes security and bug fixes as well as enhancements. For further information, refer to the release notes linked to in the References section. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Improve DTLS handshaking (CVE-2026-46917) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK: Enhance XBM image support (CVE-2026-47021) * JDK: Enhance Jar file processing (CVE-2026-47027) * JDK: Improve certification checking (CVE-2026-60147) * JDK: Enhance AWT ImagingLib (CVE-2026-47059) * JDK: Enhance Jar handling (CVE-2026-47063) * JDK: Update LCMS to 2.19 (CVE-2026-41254) Enhancement(s): * For the last couple of years, OpenJDK has used a single build shared among multiple RPMs and a tarball available on the customer portal. The single "portable" build has a release number ('p') and each RPM has its own release number ('r'). However, the RPM naming only showed the RPM release number, while the version output from the build showed the portable release number, making it unclear that they were different numbers. From this release onwards, a release field of the form 'p.r' is always used for RPMs and the version output shows 'p'. (OPENJDK-4890) Bug Fix(es): For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory covers the OpenJDK 11 ELS packages for portable Linux builds and the Eclipse Temurin build of OpenJDK 25 for Windows. The update to OpenJDK 11.0.32 addresses multiple security vulnerabilities, including CVE-2026-41254 (integer overflow in Little CMS leading to information disclosure or denial of service), CVE-2026-46968 (TLS certificate handling enhancement), CVE-2026-46917 (DTLS handshaking improvement), CVE-2026-47010 (JPEG handling enhancement), CVE-2026-47021 (XBM image support enhancement), CVE-2026-47027 and CVE-2026-47063 (Jar file processing and handling enhancements), CVE-2026-60147 (certification checking improvement), CVE-2026-47059 (AWT ImagingLib enhancement), CVE-2026-47057 (Nashorn index handling improvement), and CVE-2026-47058 (Dataview implementation enhancement). The advisory includes detailed vendor-provided patches and instructions for applying the update on Red Hat Enterprise Linux versions 7, 8, and 9. No known exploits in the wild have been reported for these vulnerabilities.
Potential Impact
The vulnerabilities addressed include potential information disclosure and denial of service via an integer overflow in the Little CMS library, as well as multiple enhancements and fixes to TLS/DTLS certificate handling, image processing, Jar file handling, and certification checking within OpenJDK. These issues could affect the security and stability of Java applications running on affected OpenJDK versions. The overall severity is rated as high by Red Hat, indicating significant security impact if unpatched.
Mitigation Recommendations
Red Hat has released official security updates for OpenJDK 11 ELS (version 11.0.32) and the Eclipse Temurin build of OpenJDK 25 (version 25.0.4) that address these vulnerabilities. Users should apply these updates promptly after ensuring all previously released errata relevant to their systems have been applied. Detailed update instructions are available in the Red Hat advisory and knowledge base articles. No additional mitigation steps are required beyond applying the official patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:42895
- Cve Count
- 9
- Additional Cves
- ["CVE-2026-46917","CVE-2026-46968","CVE-2026-47010","CVE-2026-47021","CVE-2026-47027","CVE-2026-47059","CVE-2026-47063","CVE-2026-60147"]
- State
- PUBLISHED
Threat ID: 6a6b72c19c2644c7f8474b39
Added to database: 07/30/2026, 15:50:25 UTC
Last enriched: 08/07/2026, 02:10:43 UTC
Last updated: 09/15/2026, 01:45:46 UTC
Views: 47
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.