Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Red Hat Security Advisory: OpenJDK 11.0.31 ELS Security Update for Portable Linux Builds

0
High
Published: Wed Apr 22 2026 (04/22/2026, 15:44:55 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat has released an important security update for OpenJDK 11. 0. 31 Extended Lifecycle Support (ELS) for portable Linux builds. This update addresses multiple vulnerabilities primarily related to the LIBPNG and GIFLIB libraries used within the JDK, including out-of-bounds reads, heap buffer overflows, use-after-free leading to arbitrary code execution, information disclosure, and denial of service. The update replaces the previous OpenJDK 11. 0. 30 build and includes both security fixes and bug fixes. Users of affected Red Hat OpenJDK 11 ELS versions on various architectures are advised to apply this update. No known exploits in the wild have been reported at this time.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/26/2026, 23:20:05 UTC

Technical Analysis

The Red Hat build of OpenJDK 11 (version 11.0.31) with Extended Lifecycle Support for portable Linux replaces version 11.0.30 and includes multiple security fixes. The vulnerabilities fixed include out-of-bounds reads (CVE-2025-66293), information disclosure and denial of service via integer truncation (CVE-2026-22801), heap buffer overflow (CVE-2026-25646), denial of service via buffer overflow in GIFLIB (CVE-2026-26740), arbitrary code execution due to use-after-free (CVE-2026-33416), and other issues related to out-of-bounds read/write and heap buffer over-read in LIBPNG components. Additional CVEs related to the JDK are also addressed. These vulnerabilities affect multiple architectures supported by Red Hat's OpenJDK 11 ELS packages. The update is classified as important by Red Hat Product Security.

Potential Impact

The vulnerabilities fixed in this update can lead to various impacts including out-of-bounds memory access, information disclosure, denial of service, heap buffer overflows, and arbitrary code execution. These issues affect the OpenJDK 11 runtime and development kit, potentially impacting applications running on affected Red Hat Linux systems. No known exploits in the wild have been reported. The severity of these vulnerabilities is considered high due to the possibility of arbitrary code execution and denial of service.

Mitigation Recommendations

Red Hat has released OpenJDK 11.0.31 ELS as a security update that addresses these vulnerabilities. Users should apply this update to replace the previous OpenJDK 11.0.30 build. Before applying the update, ensure all previously released relevant errata are applied. Detailed update instructions are available from Red Hat's official documentation. Since this is an official security advisory with an available update, applying the provided update is the recommended mitigation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:9255
Cve Count
15
Additional Cves
["CVE-2026-22007","CVE-2026-22013","CVE-2026-22016","CVE-2026-22018","CVE-2026-22021","CVE-2026-22695","CVE-2026-22801","CVE-2026-23865","CVE-2026-25646","CVE-2026-26740","CVE-2026-33416","CVE-2026-33636","CVE-2026-34268","CVE-2026-34282"]
Cvss Version
null

Threat ID: 6a160979e29bf47b50645838

Added to database: 5/26/2026, 8:58:33 PM

Last enriched: 5/26/2026, 11:20:05 PM

Last updated: 5/27/2026, 4:54:42 AM

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses