Red Hat Security Advisory: OpenJDK 11.0.31 ELS Security Update for Portable Linux Builds
Red Hat has released an important security update for OpenJDK 11. 0. 31 Extended Lifecycle Support (ELS) for portable Linux builds. This update addresses multiple vulnerabilities primarily related to the LIBPNG and GIFLIB libraries used within the JDK, including out-of-bounds reads, heap buffer overflows, use-after-free leading to arbitrary code execution, information disclosure, and denial of service. The update replaces the previous OpenJDK 11. 0. 30 build and includes both security fixes and bug fixes. Users of affected Red Hat OpenJDK 11 ELS versions on various architectures are advised to apply this update. No known exploits in the wild have been reported at this time.
AI Analysis
Technical Summary
The Red Hat build of OpenJDK 11 (version 11.0.31) with Extended Lifecycle Support for portable Linux replaces version 11.0.30 and includes multiple security fixes. The vulnerabilities fixed include out-of-bounds reads (CVE-2025-66293), information disclosure and denial of service via integer truncation (CVE-2026-22801), heap buffer overflow (CVE-2026-25646), denial of service via buffer overflow in GIFLIB (CVE-2026-26740), arbitrary code execution due to use-after-free (CVE-2026-33416), and other issues related to out-of-bounds read/write and heap buffer over-read in LIBPNG components. Additional CVEs related to the JDK are also addressed. These vulnerabilities affect multiple architectures supported by Red Hat's OpenJDK 11 ELS packages. The update is classified as important by Red Hat Product Security.
Potential Impact
The vulnerabilities fixed in this update can lead to various impacts including out-of-bounds memory access, information disclosure, denial of service, heap buffer overflows, and arbitrary code execution. These issues affect the OpenJDK 11 runtime and development kit, potentially impacting applications running on affected Red Hat Linux systems. No known exploits in the wild have been reported. The severity of these vulnerabilities is considered high due to the possibility of arbitrary code execution and denial of service.
Mitigation Recommendations
Red Hat has released OpenJDK 11.0.31 ELS as a security update that addresses these vulnerabilities. Users should apply this update to replace the previous OpenJDK 11.0.30 build. Before applying the update, ensure all previously released relevant errata are applied. Detailed update instructions are available from Red Hat's official documentation. Since this is an official security advisory with an available update, applying the provided update is the recommended mitigation.
Red Hat Security Advisory: OpenJDK 11.0.31 ELS Security Update for Portable Linux Builds
Description
Red Hat has released an important security update for OpenJDK 11. 0. 31 Extended Lifecycle Support (ELS) for portable Linux builds. This update addresses multiple vulnerabilities primarily related to the LIBPNG and GIFLIB libraries used within the JDK, including out-of-bounds reads, heap buffer overflows, use-after-free leading to arbitrary code execution, information disclosure, and denial of service. The update replaces the previous OpenJDK 11. 0. 30 build and includes both security fixes and bug fixes. Users of affected Red Hat OpenJDK 11 ELS versions on various architectures are advised to apply this update. No known exploits in the wild have been reported at this time.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat build of OpenJDK 11 (version 11.0.31) with Extended Lifecycle Support for portable Linux replaces version 11.0.30 and includes multiple security fixes. The vulnerabilities fixed include out-of-bounds reads (CVE-2025-66293), information disclosure and denial of service via integer truncation (CVE-2026-22801), heap buffer overflow (CVE-2026-25646), denial of service via buffer overflow in GIFLIB (CVE-2026-26740), arbitrary code execution due to use-after-free (CVE-2026-33416), and other issues related to out-of-bounds read/write and heap buffer over-read in LIBPNG components. Additional CVEs related to the JDK are also addressed. These vulnerabilities affect multiple architectures supported by Red Hat's OpenJDK 11 ELS packages. The update is classified as important by Red Hat Product Security.
Potential Impact
The vulnerabilities fixed in this update can lead to various impacts including out-of-bounds memory access, information disclosure, denial of service, heap buffer overflows, and arbitrary code execution. These issues affect the OpenJDK 11 runtime and development kit, potentially impacting applications running on affected Red Hat Linux systems. No known exploits in the wild have been reported. The severity of these vulnerabilities is considered high due to the possibility of arbitrary code execution and denial of service.
Mitigation Recommendations
Red Hat has released OpenJDK 11.0.31 ELS as a security update that addresses these vulnerabilities. Users should apply this update to replace the previous OpenJDK 11.0.30 build. Before applying the update, ensure all previously released relevant errata are applied. Detailed update instructions are available from Red Hat's official documentation. Since this is an official security advisory with an available update, applying the provided update is the recommended mitigation.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:9255
- Cve Count
- 15
- Additional Cves
- ["CVE-2026-22007","CVE-2026-22013","CVE-2026-22016","CVE-2026-22018","CVE-2026-22021","CVE-2026-22695","CVE-2026-22801","CVE-2026-23865","CVE-2026-25646","CVE-2026-26740","CVE-2026-33416","CVE-2026-33636","CVE-2026-34268","CVE-2026-34282"]
- Cvss Version
- null
Threat ID: 6a160979e29bf47b50645838
Added to database: 5/26/2026, 8:58:33 PM
Last enriched: 5/26/2026, 11:20:05 PM
Last updated: 5/27/2026, 4:54:42 AM
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.