Red Hat Security Advisory: OpenJDK 11.0.30 ELS Security Update for Windows Builds
Red Hat has released an update for its OpenJDK 11. 0. 30 Extended Lifecycle Support (ELS) Windows builds addressing multiple security vulnerabilities. These include buffer overflow issues in the LIBPNG library and enhancements to JMX connections, URI handling, HTTP server request processing, and certificate checking. The update replaces the previous 11. 0. 29 build and includes security fixes and bug enhancements. The advisory rates the overall security impact as moderate. No known exploits in the wild have been reported. Users of affected OpenJDK 11 ELS versions on Red Hat Enterprise Linux are advised to apply this update following Red Hat's guidance.
AI Analysis
Technical Summary
This Red Hat security advisory covers the OpenJDK 11.0.30 ELS release for Windows builds, which replaces version 11.0.29. It addresses six CVEs: two buffer overflow vulnerabilities in the LIBPNG library (CVE-2025-64720 and CVE-2025-65018), and four additional vulnerabilities related to JMX connections (CVE-2026-21925), URI handling (CVE-2026-21932), HTTP server request handling (CVE-2026-21933), and certificate checking (CVE-2026-21945). The advisory rates the security impact as moderate and provides a link to detailed release notes and update instructions. The update is applicable to multiple architectures of Red Hat Enterprise Linux running OpenJDK 11 ELS. No CVSS scores are provided within the advisory, and no known active exploits have been reported.
Potential Impact
The vulnerabilities fixed in this update include heap and standard buffer overflows in the LIBPNG library, which could potentially lead to memory corruption. Other fixes improve security in JMX connections, URI handling, HTTP server request processing, and certificate validation. The overall security impact is rated as moderate by Red Hat. There are no reports of known exploits in the wild targeting these vulnerabilities at this time.
Mitigation Recommendations
Red Hat has released an official update for OpenJDK 11.0.30 ELS that addresses these vulnerabilities. Users should apply this update to replace the previous 11.0.29 build. Before applying the update, ensure all previously released errata relevant to your system are installed. Detailed update instructions are available at Red Hat's official documentation: https://access.redhat.com/articles/11258. No additional mitigation steps are indicated or required beyond applying the official update.
Red Hat Security Advisory: OpenJDK 11.0.30 ELS Security Update for Windows Builds
Description
Red Hat has released an update for its OpenJDK 11. 0. 30 Extended Lifecycle Support (ELS) Windows builds addressing multiple security vulnerabilities. These include buffer overflow issues in the LIBPNG library and enhancements to JMX connections, URI handling, HTTP server request processing, and certificate checking. The update replaces the previous 11. 0. 29 build and includes security fixes and bug enhancements. The advisory rates the overall security impact as moderate. No known exploits in the wild have been reported. Users of affected OpenJDK 11 ELS versions on Red Hat Enterprise Linux are advised to apply this update following Red Hat's guidance.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory covers the OpenJDK 11.0.30 ELS release for Windows builds, which replaces version 11.0.29. It addresses six CVEs: two buffer overflow vulnerabilities in the LIBPNG library (CVE-2025-64720 and CVE-2025-65018), and four additional vulnerabilities related to JMX connections (CVE-2026-21925), URI handling (CVE-2026-21932), HTTP server request handling (CVE-2026-21933), and certificate checking (CVE-2026-21945). The advisory rates the security impact as moderate and provides a link to detailed release notes and update instructions. The update is applicable to multiple architectures of Red Hat Enterprise Linux running OpenJDK 11 ELS. No CVSS scores are provided within the advisory, and no known active exploits have been reported.
Potential Impact
The vulnerabilities fixed in this update include heap and standard buffer overflows in the LIBPNG library, which could potentially lead to memory corruption. Other fixes improve security in JMX connections, URI handling, HTTP server request processing, and certificate validation. The overall security impact is rated as moderate by Red Hat. There are no reports of known exploits in the wild targeting these vulnerabilities at this time.
Mitigation Recommendations
Red Hat has released an official update for OpenJDK 11.0.30 ELS that addresses these vulnerabilities. Users should apply this update to replace the previous 11.0.29 build. Before applying the update, ensure all previously released errata relevant to your system are installed. Detailed update instructions are available at Red Hat's official documentation: https://access.redhat.com/articles/11258. No additional mitigation steps are indicated or required beyond applying the official update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:0849
- Cve Count
- 6
- Additional Cves
- ["CVE-2025-65018","CVE-2026-21925","CVE-2026-21932","CVE-2026-21933","CVE-2026-21945"]
- Cvss Version
- null
Threat ID: 6a1f4e86e29bf47b5007f2d2
Added to database: 6/2/2026, 9:43:34 PM
Last enriched: 6/2/2026, 9:59:15 PM
Last updated: 6/3/2026, 5:09:39 AM
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.