{"cves":[{"id":"CVE-2026-60161","published":"2026-07-21T22:17:00","updated_at":"2026-08-06T23:45:50.775062+00:00","description":"\nVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization\n(component: Core). The supported version that is affected is 7.2.12.\nEasily exploitable vulnerability allows unauthenticated attacker with logon\nto the infrastructure where Oracle VM VirtualBox executes to compromise\nOracle VM VirtualBox. Successful attacks require human interaction from a\nperson other than the attacker. Successful attacks of this vulnerability\ncan result in unauthorized ability to cause a hang or frequently repeatable\ncrash (complete DOS) of Oracle VM VirtualBox as well as unauthorized\nupdate, insert or delete access to some of Oracle VM VirtualBox accessible\ndata. CVSS 3.1 Base Score 6.1 (Integrity and Availability impacts). CVSS\nVector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-60161"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-60160","published":"2026-07-21T22:17:00","updated_at":"2026-08-06T23:45:42.188635+00:00","description":"\nVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization\n(component: Core). The supported version that is affected is 7.2.12.\nEasily exploitable vulnerability allows high privileged attacker with logon\nto the infrastructure where Oracle VM VirtualBox executes to compromise\nOracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox,\nattacks may significantly impact additional products (scope change).\nSuccessful attacks of this vulnerability can result in unauthorized read\naccess to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base\nScore 3.2 (Confidentiality impacts). CVSS Vector:\n(CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.2,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-60160"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-60159","published":"2026-07-21T22:17:00","updated_at":"2026-08-06T23:45:38.319347+00:00","description":"\nVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization\n(component: Core). The supported version that is affected is 7.2.12.\nDifficult to exploit vulnerability allows high privileged attacker with\nlogon to the infrastructure where Oracle VM VirtualBox executes to\ncompromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM\nVirtualBox, attacks may significantly impact additional products (scope\nchange). Successful attacks of this vulnerability can result in takeover\nof Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality,\nIntegrity and Availability impacts). CVSS Vector:\n(CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-60159"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-60158","published":"2026-07-21T22:17:00","updated_at":"2026-08-06T23:45:55.716567+00:00","description":"\nVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization\n(component: Core). The supported version that is affected is 7.2.12.\nDifficult to exploit vulnerability allows low privileged attacker with\nlogon to the infrastructure where Oracle VM VirtualBox executes to\ncompromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM\nVirtualBox, attacks may significantly impact additional products (scope\nchange). Successful attacks of this vulnerability can result in\nunauthorized creation, deletion or modification access to critical data or\nall Oracle VM VirtualBox accessible data and unauthorized ability to cause\na partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1\nBase Score 6.4 (Integrity and Availability impacts). CVSS Vector:\n(CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":6.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-60158"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-60155","published":"2026-07-21T22:17:00","updated_at":"2026-08-06T23:45:42.188635+00:00","description":"\nVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization\n(component: Core). The supported version that is affected is 7.2.12.\nDifficult to exploit vulnerability allows high privileged attacker with\nlogon to the infrastructure where Oracle VM VirtualBox executes to\ncompromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM\nVirtualBox, attacks may significantly impact additional products (scope\nchange). Successful attacks of this vulnerability can result in takeover\nof Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality,\nIntegrity and Availability impacts). CVSS Vector:\n(CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-60155"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-60150","published":"2026-07-21T22:17:00","updated_at":"2026-08-06T23:45:38.319347+00:00","description":"\nVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization\n(component: Core). The supported version that is affected is 7.2.12.\nEasily exploitable vulnerability allows low privileged attacker with logon\nto the infrastructure where Oracle VM VirtualBox executes to compromise\nOracle VM VirtualBox. Successful attacks of this vulnerability can result\nin takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8\n(Confidentiality, Integrity and Availability impacts). CVSS Vector:\n(CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-60150"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-60147","published":"2026-07-21T22:17:00","updated_at":"2026-08-31T18:14:07.403040+00:00","description":"\nVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM\nEnterprise Edition product of Oracle Java SE (component: Security).\nSupported versions that are affected are Oracle Java SE: 8u491, 8u491-perf,\n11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19\nand 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily\nexploitable vulnerability allows unauthenticated attacker with network\naccess via multiple protocols to compromise Oracle Java SE, Oracle GraalVM\nfor JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this\nvulnerability can result in unauthorized update, insert or delete access\nto some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM\nEnterprise Edition accessible data as well as unauthorized read access to\na subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM\nEnterprise Edition accessible data. Note: This vulnerability can be\nexploited by using APIs in the specified Component, e.g., through a web\nservice which supplies data to the APIs. This vulnerability also applies to\nJava deployments, typically in clients running sandboxed Java Web Start\napplications or sandboxed Java applets, that load and run untrusted code\n(e.g., code that comes from the internet) and rely on the Java sandbox for\nsecurity. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).\nCVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-60147","https://openjdk.org/groups/vulnerability/advisories/2026-07-21","https://ubuntu.com/security/notices/USN-8673-1","https://ubuntu.com/security/notices/USN-8674-1","https://ubuntu.com/security/notices/USN-8676-1","https://ubuntu.com/security/notices/USN-8677-1","https://ubuntu.com/security/notices/USN-8681-1","https://ubuntu.com/security/notices/USN-8689-1","https://ubuntu.com/security/notices/USN-8693-1","https://ubuntu.com/security/notices/USN-8694-1","https://ubuntu.com/security/notices/USN-8695-1"],"bugs":[""],"patches":{"openjdk-8":[],"openjdk-9":[],"openjdk-lts":[],"openjdk-13":[],"openjdk-16":[],"openjdk-17":[],"openjdk-17-crac":[],"openjdk-18":[],"openjdk-21":[],"openjdk-21-crac":[],"openjdk-25":[],"openjdk-26":[]},"tags":{},"packages":[{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8u502-ga~us1-0ubuntu1~18.04","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"8u502-ga~us1-0ubuntu1~20.04","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"8u502-ga~us1-0ubuntu1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8u502-ga~us1-0ubuntu1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"8u502-ga~us1-0ubuntu1~26.04","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u502-ga~us1-0ubuntu1~16.04","component":null,"pocket":"esm-infra-legacy"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"no longer supported by upstream","component":null,"pocket":"security"}]},{"name":"openjdk-lts","source":"https://ubuntu.com/security/cve?package=openjdk-lts","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-lts","debian":"https://tracker.debian.org/pkg/openjdk-lts","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"11.0.32+9-1ubuntu1~18.04","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"11.0.32+9-1ubuntu1~20.04","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"11.0.32+9-1ubuntu1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"11.0.32+9-1ubuntu1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"11.0.32+9-1ubuntu1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-13","source":"https://ubuntu.com/security/cve?package=openjdk-13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-13","debian":"https://tracker.debian.org/pkg/openjdk-13","statuses":[{"release_codename":"focal","status":"ignored","description":"superseded by openjdk-17","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-16","source":"https://ubuntu.com/security/cve?package=openjdk-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-16","debian":"https://tracker.debian.org/pkg/openjdk-16","statuses":[{"release_codename":"focal","status":"ignored","description":"superseded by openjdk-17","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-17","source":"https://ubuntu.com/security/cve?package=openjdk-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-17","debian":"https://tracker.debian.org/pkg/openjdk-17","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"17.0.20+8-1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"17.0.20+8-1~24.04","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"17.0.20+8-1~18.04","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"17.0.20+8-1~20.04","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"released","description":"17.0.20+8-1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-17-crac","source":"https://ubuntu.com/security/cve?package=openjdk-17-crac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-17-crac","debian":"https://tracker.debian.org/pkg/openjdk-17-crac","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"17.0.20+8-0ubuntu1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-18","source":"https://ubuntu.com/security/cve?package=openjdk-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-18","debian":"https://tracker.debian.org/pkg/openjdk-18","statuses":[{"release_codename":"jammy","status":"ignored","description":"superseded by openjdk-19","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-21","source":"https://ubuntu.com/security/cve?package=openjdk-21","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-21","debian":"https://tracker.debian.org/pkg/openjdk-21","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"21.0.12+8-1~20.04","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"21.0.12+8-1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"21.0.12+8-1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"21.0.12+8-1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-21-crac","source":"https://ubuntu.com/security/cve?package=openjdk-21-crac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-21-crac","debian":"https://tracker.debian.org/pkg/openjdk-21-crac","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"21.0.12+8-0ubuntu1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-25","source":"https://ubuntu.com/security/cve?package=openjdk-25","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-25","debian":"https://tracker.debian.org/pkg/openjdk-25","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"25.0.4+7-1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"25.0.4+7-1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"25.0.4+7-1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-26","source":"https://ubuntu.com/security/cve?package=openjdk-26","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-26","debian":"https://tracker.debian.org/pkg/openjdk-26","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"26.0.2+10-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"26.0.2+10-2~26.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-8673-1","USN-8681-1","USN-8677-1","USN-8676-1","USN-8674-1","USN-8689-1","USN-8693-1","USN-8694-1","USN-8695-1"],"notices":[{"id":"USN-8673-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T13:25:30.050362","description":"It was discovered that the JSSE component of OpenJDK 8 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the ImageIO component of OpenJDK 8 did not correctly\nauthorize users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 8 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 8 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 8 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 8 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the Scripting component of OpenJDK 8 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to cause a denial of service or to read or modify sensitive data.\n(CVE-2026-47057, CVE-2026-47058)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 8 did\nnot correctly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"bionic":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~18.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"}],"xenial":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~16.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre-jamvm","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-47057","CVE-2026-60147","CVE-2026-47027","CVE-2026-41254","CVE-2026-47058","CVE-2026-47010","CVE-2026-47059","CVE-2026-47063","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8681-1","title":"OpenJDK 25 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 25.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running\nJava applications to make all the necessary changes.","references":[],"published":"2026-08-26T01:40:39.865697","description":"It was discovered that the JSSE component of OpenJDK 25 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 25 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 25 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-47063)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 25 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly use\nthis issue to cause a denial of service. (CVE-2026-41254)","is_hidden":false,"release_packages":{"jammy":[{"name":"openjdk-25","version":"25.0.4+7-1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-25-demo","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-doc","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-jdk","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-jdk-headless","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-jre","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-jre-headless","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-jre-zero","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-source","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-testsupport","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-25","version":"25.0.4+7-1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-25-demo","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-doc","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-jdk","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-jdk-headless","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-jre","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-jre-headless","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-jre-zero","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-source","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-testsupport","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-25","version":"25.0.4+7-1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-25-demo","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-doc","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-jdk","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-jdk-headless","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-jre","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-jre-headless","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-jre-zero","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-source","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-testsupport","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-47027","CVE-2026-41254","CVE-2026-47010","CVE-2026-47059","CVE-2026-46917","CVE-2026-47063","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8677-1","title":"OpenJDK 21 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 21.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T17:06:53.057126","description":"It was discovered that the JSSE component of OpenJDK 21 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 21 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 21 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 21 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 21 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 21 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 21 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the 2D (Little CMS) component of OpenJDK 21 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly use\nthis issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"focal":[{"name":"openjdk-21","version":"21.0.12+8-1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-21-demo","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-doc","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-jdk","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-jdk-headless","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-jre","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-jre-headless","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-jre-zero","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-source","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-testsupport","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"openjdk-21","version":"21.0.12+8-1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-21-demo","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-doc","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-jdk","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-jdk-headless","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-jre","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-jre-headless","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-jre-zero","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-source","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-testsupport","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-21","version":"21.0.12+8-1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-21-demo","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-doc","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-jdk","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-jdk-headless","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-jre","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-jre-headless","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-jre-zero","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-source","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-testsupport","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-21","version":"21.0.12+8-1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-21-demo","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-doc","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-jdk","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-jdk-headless","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-jre","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-jre-headless","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-jre-zero","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-source","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-testsupport","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-46917","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47063","CVE-2026-47059","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8676-1","title":"OpenJDK 17 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 17.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T16:49:57.919538","description":"It was discovered that the JSSE component of OpenJDK 17 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 17 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 17 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 17 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 17 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 17 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 17 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the 2D (Little CMS) component of OpenJDK 17 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"bionic":[{"name":"openjdk-17","version":"17.0.20+8-1~18.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-17-demo","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-doc","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jdk","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre-headless","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre-zero","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-source","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"openjdk-17","version":"17.0.20+8-1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-17-demo","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-doc","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jdk","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre-headless","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre-zero","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-source","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"openjdk-17","version":"17.0.20+8-1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-17-demo","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-doc","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-jdk","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-jre","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-jre-headless","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-jre-zero","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-source","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-17","version":"17.0.20+8-1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-17-demo","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-doc","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-jdk","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-jre","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-jre-headless","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-jre-zero","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-source","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-17","version":"17.0.20+8-1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-17-demo","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-doc","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-jdk","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-jre","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-jre-headless","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-jre-zero","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-source","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-46917","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47063","CVE-2026-47059","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8674-1","title":"OpenJDK 11 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 11.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T13:43:19.367555","description":"It was discovered that the JSSE component of OpenJDK 11 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 11 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 11 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 11 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 11 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 11 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 11 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the Scripting component of OpenJDK 11 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to cause a denial of service or to read or modify sensitive data.\n(CVE-2026-47057, CVE-2026-47058)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 11 did\nnot correctly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"bionic":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~18.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-46917","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47058","CVE-2026-47063","CVE-2026-46968","CVE-2026-47059","CVE-2026-47057","CVE-2026-47021"]},{"id":"USN-8689-1","title":"OpenJDK 26 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 26.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-31T00:41:06.626029","description":"It was discovered that the JSSE component of OpenJDK 26 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 26 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 26 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 26 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 26 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 26 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 26 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 26 did\nnot correctly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)","is_hidden":false,"release_packages":{"resolute":[{"name":"openjdk-26","version":"26.0.2+10-2~26.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-26-demo","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-doc","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-jdk","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-jdk-headless","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-jre","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-jre-headless","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-jre-zero","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-source","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-testsupport","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-46917","CVE-2026-60147","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47063","CVE-2026-47059","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8693-1","title":"CRaC JDK 17 vulnerabilities","summary":"Several security issues were fixed in CRaC JDK 17.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-31T10:33:52.676296","description":"It was discovered that the JSSE component of CRaC JDK 17 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of CRaC JDK 17 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of CRaC JDK 17 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of CRaC JDK 17 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of CRaC JDK 17 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of CRaC JDK 17 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of CRaC JDK 17 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the 2D (Little CMS) component of CRaC JDK 17 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"resolute":[{"name":"openjdk-17-crac","version":"17.0.20+8-0ubuntu1~26.04","description":"Open Source Java implementation with Coordinated Restore at Checkpoints","is_source":true},{"name":"openjdk-17-crac-demo","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-doc","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-jdk","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-jdk-headless","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-jre","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-jre-headless","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-jre-zero","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-source","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-46917","CVE-2026-60147","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47063","CVE-2026-47059","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8694-1","title":"CRaC JDK 21 vulnerabilities","summary":"Several security issues were fixed in CRaC JDK 21.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-31T10:38:07.326530","description":"It was discovered that the JSSE component of CRaC JDK 21 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of CRaC JDK 21 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of CRaC JDK 21 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of CRaC JDK 21 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of CRaC JDK 21 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of CRaC JDK 21 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of CRaC JDK 21 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the 2D (Little CMS) component of CRaC JDK 21 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"resolute":[{"name":"openjdk-21-crac","version":"21.0.12+8-0ubuntu1~26.04","description":"Open Source Java implementation with Coordinated Restore at Checkpoints","is_source":true},{"name":"openjdk-21-crac-demo","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-doc","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-jdk","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-jdk-headless","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-jre","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-jre-headless","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-jre-zero","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-source","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-testsupport","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-46917","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47063","CVE-2026-47059","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8695-1","title":"CRaC JDK 25 vulnerabilities","summary":"Several security issues were fixed in CRaC JDK 25.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-31T10:43:21.840556","description":"It was discovered that the JSSE component of CRaC JDK 25 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of CRaC JDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of CRaC JDK 25 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of CRaC JDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of CRaC JDK 25 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of CRaC JDK 25 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of CRaC JDK 25 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the 2D (Little CMS) component of CRaC JDK 25 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"resolute":[{"name":"openjdk-25-crac","version":"25.0.4+7-0ubuntu1~26.04","description":"Open Source Java implementation with Coordinated Restore at Checkpoints","is_source":true},{"name":"openjdk-25-crac-demo","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-doc","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-jdk","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-jdk-headless","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-jre","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-jre-headless","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-jre-zero","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-source","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-testsupport","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-47027","CVE-2026-41254","CVE-2026-47010","CVE-2026-47059","CVE-2026-46917","CVE-2026-47063","CVE-2026-46968","CVE-2026-47021"]}]},{"id":"CVE-2026-60145","published":"2026-07-21T22:17:00","updated_at":"2026-08-31T13:59:24.909408+00:00","description":"\nVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL\n(component: Server: Optimizer). Supported versions that are affected are\nMySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47,\n8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high\nprivileged attacker with network access via multiple protocols to\ncompromise MySQL Server, MySQL Cluster. Successful attacks of this\nvulnerability can result in unauthorized ability to cause a hang or\nfrequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster.\nCVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector:\n(CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","ubuntu_description":"","notes":[{"author":"iconstantin","note":"since mysql versions 5.7 and earlier are no longer supported\nupstream, we are unable to update them to address security\nissues,\nmarking as ignored.\nmariadb 5.5, 10.0, 10.1, and 10.3 are end of life and no\nlonger supported upstream - marking as ignored."}],"codename":null,"priority":"medium","cvss3":4.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":4.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-60145","https://www.oracle.com/security-alerts/cpujul2026.html","https://ubuntu.com/security/notices/USN-8700-1"],"bugs":[""],"patches":{"mysql-5.5":[],"mysql-5.7":[],"mysql-8.0":[],"mysql-8.4":[],"mariadb":[],"mariadb-10.0":[],"mariadb-10.1":[],"mariadb-10.3":[],"mariadb-10.6":[],"percona-xtradb-cluster-5.6":[],"percona-server-5.6":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"trusty","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-5.7","source":"https://ubuntu.com/security/cve?package=mysql-5.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.7","debian":"https://tracker.debian.org/pkg/mysql-5.7","statuses":[{"release_codename":"xenial","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-8.0","source":"https://ubuntu.com/security/cve?package=mysql-8.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-8.0","debian":"https://tracker.debian.org/pkg/mysql-8.0","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"8.0.46-0ubuntu0.22.04.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.0.46-0ubuntu0.24.04.4","component":null,"pocket":"security"}]},{"name":"mysql-8.4","source":"https://ubuntu.com/security/cve?package=mysql-8.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-8.4","debian":"https://tracker.debian.org/pkg/mysql-8.4","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"8.4.11-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"mariadb","source":"https://ubuntu.com/security/cve?package=mariadb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb","debian":"https://tracker.debian.org/pkg/mariadb","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.0","source":"https://ubuntu.com/security/cve?package=mariadb-10.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-10.0","debian":"https://tracker.debian.org/pkg/mariadb-10.0","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.1","source":"https://ubuntu.com/security/cve?package=mariadb-10.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-10.1","debian":"https://tracker.debian.org/pkg/mariadb-10.1","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.3","source":"https://ubuntu.com/security/cve?package=mariadb-10.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-10.3","debian":"https://tracker.debian.org/pkg/mariadb-10.3","statuses":[{"release_codename":"focal","status":"ignored","description":"no more upstream support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.6","source":"https://ubuntu.com/security/cve?package=mariadb-10.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-10.6","debian":"https://tracker.debian.org/pkg/mariadb-10.6","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"percona-xtradb-cluster-5.6","source":"https://ubuntu.com/security/cve?package=percona-xtradb-cluster-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=percona-xtradb-cluster-5.6","debian":"https://tracker.debian.org/pkg/percona-xtradb-cluster-5.6","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"percona-server-5.6","source":"https://ubuntu.com/security/cve?package=percona-server-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=percona-server-5.6","debian":"https://tracker.debian.org/pkg/percona-server-5.6","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8700-1"],"notices":[{"id":"USN-8700-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.","instructions":"This update may use a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-08-31T12:09:27.424365","description":"Multiple security issues were discovered in MySQL.\n\nMySQL has been updated to 8.4.11 in Ubuntu 26.04 LTS. Ubuntu 22.04 LTS and\nUbuntu 24.04 LTS packages have been updated with backported patches.\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\n\nhttps://dev.mysql.com/doc/relnotes/mysql/8.4/en/news-8-4-11.html\nhttps://www.oracle.com/security-alerts/cpujul2026.html","is_hidden":false,"release_packages":{"jammy":[{"name":"mysql-8.0","version":"8.0.46-0ubuntu0.22.04.4","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"libmysqlclient21","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-client","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-client-8.0","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-client-core-8.0","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-router","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-server","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-server-8.0","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-server-core-8.0","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-source-8.0","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-testsuite","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-testsuite-8.0","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"}],"noble":[{"name":"mysql-8.0","version":"8.0.46-0ubuntu0.24.04.4","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"libmysqlclient21","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-client","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-client-8.0","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-client-core-8.0","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-router","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-server","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-server-8.0","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-server-core-8.0","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-source-8.0","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-testsuite","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-testsuite-8.0","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"}],"resolute":[{"name":"mysql-8.4","version":"8.4.11-0ubuntu0.26.04.1","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"libmysqlclient24","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"mysql-client","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"mysql-client-core","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"mysql-router","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"mysql-server","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"mysql-server-core","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"mysql-source","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"mysql-testsuite","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-46936","CVE-2026-60183","CVE-2026-60585","CVE-2026-47023","CVE-2026-60331","CVE-2026-60163","CVE-2026-60315","CVE-2026-60177","CVE-2026-60184","CVE-2026-60188","CVE-2026-60316","CVE-2026-60145","CVE-2026-47052","CVE-2026-61081","CVE-2026-60332","CVE-2026-60178","CVE-2026-60187","CVE-2026-60186","CVE-2026-60190","CVE-2026-61096","CVE-2026-60182","CVE-2026-61094","CVE-2026-61109","CVE-2026-60189","CVE-2026-60747","CVE-2026-47064","CVE-2026-47012","CVE-2026-60191","CVE-2026-60185"]}]},{"id":"CVE-2026-56816","published":"2026-07-21T22:17:00","updated_at":"2026-08-07T01:59:59.250658+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to 4.2.16.Final, Netty's `Http3FrameCodec`\nbuffers incoming data for HTTP/3 reserved frame types up to the\nwire-specified payload length without limits; `decodeFrame` trusts\n`payLoadLength`, allowing an attacker to open multiple QUIC streams and\nsend reserved frames with very large payload lengths to cause memory\nexhaustion and denial of service. This issue is fixed in version\n4.2.16.Final.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-56816","https://github.com/netty/netty/security/advisories/GHSA-hpcc-26xq-25fv"],"bugs":[""],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-56746","published":"2026-07-21T22:17:00","updated_at":"2026-08-07T01:59:59.250658+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Versions 4.2.0.Final through 4.2.15.Final and\n4.1.0.Final through 4.1.135.Final, are vulnerable to security control\nbypass during the origin evaluation process. CorsHandler provides a\nshortCircuit() configuration designed to reject unauthorized cross-origin\nrequests immediately, acting as a security control before requests reach\nthe application. However, due to a logical operator error in the origin\nevaluation process, this protection can be entirely bypassed. An attacker\ncan bypass the short-circuit mechanism by sending a request with an Origin:\nnull header. This failure forwards unauthorized requests to the backend\napplication, bypassing intended access controls. This issue is fixed in\nversions 4.1.136.Final and 4.2.16.Final.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-56746","https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5"],"bugs":[""],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-56745","published":"2026-07-21T22:17:00","updated_at":"2026-08-07T02:00:04.205433+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. In versions 4.2.0.Final through 4.2.15.Final and\n4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's\nSPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a\nclient-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the\npartially constructed `FullHttpRequest` in `messageMap`; when the remote\npeer sends `RST_STREAM` for that stream or the accumulated content exceeds\n`maxContentLength`, the decoder removes the entry but does not release the\npooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in\nversions 4.1.136.Final and 4.2.16.Final.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-56745","https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq"],"bugs":[""],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55851","published":"2026-07-21T22:17:00","updated_at":"2026-08-07T01:59:59.250658+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. In versions 4.2.0.Final up to (but not including)\n4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the\n`HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs protocol\nversion detection by reading the 13th byte as a signed Java `byte` and\nwidening it to `int` without masking; a PROXY protocol v2 binary prefix\nfollowed by version byte `0xFF` sign-extends to `-1`, collides with the\ndecoder's need-more-data sentinel, and causes `ByteToMessageDecoder` to\naccumulate inbound bytes in an unbounded `cumulation` buffer until direct\nmemory is exhausted. This issue is fixed in versions 4.1.136.Final and\n4.2.16.Final.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55851","https://github.com/netty/netty/security/advisories/GHSA-q6cq-mhr2-jmr5"],"bugs":[""],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47251","published":"2026-07-21T22:17:00","updated_at":"2026-08-07T05:44:45.166237+00:00","description":"\nlibheif is a HEIF and AVIF file format decoder and encoder. The fix for\nCVE-2026-3949 (commit `b97c8b5`, PR #1712) introduced an integer overflow\nin the very security check it added. The check itself can be bypassed,\nallowing a crafted HEIF file with a VVC track to trigger the same\nout-of-bounds heap read that CVE-2026-3949 was meant to prevent. This is a\nseparate, currently-unpatched vulnerability. Issue #1712 was closed as\nfixed without testing the edge case where `size` is near `UINT32_MAX`.\nVersion 1.22.0 patches the issue.","ubuntu_description":"","notes":[{"author":"kkernick","note":"This vulnerability was introduced by the fix for CVE-2026-3949\nWhich does not affect Ubuntu packages."}],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.1,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47251","https://github.com/strukturag/libheif/security/advisories/GHSA-p6q9-fhf2-vj9v"],"bugs":[""],"patches":{"libheif":[]},"tags":{},"packages":[{"name":"libheif","source":"https://ubuntu.com/security/cve?package=libheif","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libheif","debian":"https://tracker.debian.org/pkg/libheif","statuses":[{"release_codename":"upstream","status":"released","description":"1.23.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"see notes","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47247","published":"2026-07-21T22:17:00","updated_at":"2026-08-07T05:36:45.658132+00:00","description":"\nlibheif is a HEIF and AVIF file format decoder and encoder. Prior to\nversion 1.22.0, two bugs in libheif chain to leak process heap memory as\nvisible pixel values in decoded grid images. An attacker who uploads a\ncrafted AVIF/HEIC file to any server-side image processor (WordPress,\nSharp/libvips, ImageMagick, etc.) can recover heap data - including library\nfunction pointers sufficient to defeat ASLR, or any other secret - from the\npublicly-downloadable transcoded JPEG/PNG/WebP output. Local attack vectors\nare also possible. Version 1.22.0 fixes the issue.","ubuntu_description":"","notes":[{"author":"kkernick","note":"This vulnerability shares the same fix as CVE-2026-32814."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47247","https://github.com/strukturag/libheif/security/advisories/GHSA-2vh6-whr3-cmq3"],"bugs":[""],"patches":{"libheif":["upstream: https://github.com/strukturag/libheif/commit/6aca89d76a5118bd47adcb5b83e7b01a32134985"]},"tags":{},"packages":[{"name":"libheif","source":"https://ubuntu.com/security/cve?package=libheif","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libheif","debian":"https://tracker.debian.org/pkg/libheif","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.6.1-1ubuntu0.1~esm3","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"1.12.0-2ubuntu0.1~esm3","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"1.17.6-1ubuntu4.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.20.2-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.21.2-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.22.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47064","published":"2026-07-21T22:17:00","updated_at":"2026-08-31T13:53:44.765033+00:00","description":"\nVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL\n(component: Server: Optimizer). Supported versions that are affected are\nMySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47,\n8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows low\nprivileged attacker with network access via multiple protocols to\ncompromise MySQL Server, MySQL Cluster. Successful attacks of this\nvulnerability can result in unauthorized ability to cause a hang or\nfrequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster.\nCVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector:\n(CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","ubuntu_description":"","notes":[{"author":"iconstantin","note":"since mysql versions 5.7 and earlier are no longer supported\nupstream, we are unable to update them to address security\nissues,\nmarking as ignored.\nmariadb 5.5, 10.0, 10.1, and 10.3 are end of life and no\nlonger supported upstream - marking as ignored."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47064","https://ubuntu.com/security/notices/USN-8700-1"],"bugs":[""],"patches":{"mysql-5.5":[],"mysql-5.7":[],"mysql-8.0":[],"mysql-8.4":[],"mariadb":[],"mariadb-10.0":[],"mariadb-10.1":[],"mariadb-10.3":[],"mariadb-10.6":[],"percona-xtradb-cluster-5.6":[],"percona-server-5.6":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"trusty","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-5.7","source":"https://ubuntu.com/security/cve?package=mysql-5.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.7","debian":"https://tracker.debian.org/pkg/mysql-5.7","statuses":[{"release_codename":"xenial","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mysql-8.0","source":"https://ubuntu.com/security/cve?package=mysql-8.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-8.0","debian":"https://tracker.debian.org/pkg/mysql-8.0","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"8.0.46-0ubuntu0.22.04.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.0.46-0ubuntu0.24.04.4","component":null,"pocket":"security"}]},{"name":"mysql-8.4","source":"https://ubuntu.com/security/cve?package=mysql-8.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-8.4","debian":"https://tracker.debian.org/pkg/mysql-8.4","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"8.4.11-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"mariadb","source":"https://ubuntu.com/security/cve?package=mariadb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb","debian":"https://tracker.debian.org/pkg/mariadb","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.0","source":"https://ubuntu.com/security/cve?package=mariadb-10.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-10.0","debian":"https://tracker.debian.org/pkg/mariadb-10.0","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.1","source":"https://ubuntu.com/security/cve?package=mariadb-10.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-10.1","debian":"https://tracker.debian.org/pkg/mariadb-10.1","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.3","source":"https://ubuntu.com/security/cve?package=mariadb-10.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-10.3","debian":"https://tracker.debian.org/pkg/mariadb-10.3","statuses":[{"release_codename":"focal","status":"ignored","description":"no more upstream support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.6","source":"https://ubuntu.com/security/cve?package=mariadb-10.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-10.6","debian":"https://tracker.debian.org/pkg/mariadb-10.6","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"percona-xtradb-cluster-5.6","source":"https://ubuntu.com/security/cve?package=percona-xtradb-cluster-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=percona-xtradb-cluster-5.6","debian":"https://tracker.debian.org/pkg/percona-xtradb-cluster-5.6","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"percona-server-5.6","source":"https://ubuntu.com/security/cve?package=percona-server-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=percona-server-5.6","debian":"https://tracker.debian.org/pkg/percona-server-5.6","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8700-1"],"notices":[{"id":"USN-8700-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.","instructions":"This update may use a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-08-31T12:09:27.424365","description":"Multiple security issues were discovered in MySQL.\n\nMySQL has been updated to 8.4.11 in Ubuntu 26.04 LTS. Ubuntu 22.04 LTS and\nUbuntu 24.04 LTS packages have been updated with backported patches.\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\n\nhttps://dev.mysql.com/doc/relnotes/mysql/8.4/en/news-8-4-11.html\nhttps://www.oracle.com/security-alerts/cpujul2026.html","is_hidden":false,"release_packages":{"jammy":[{"name":"mysql-8.0","version":"8.0.46-0ubuntu0.22.04.4","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"libmysqlclient21","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-client","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-client-8.0","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-client-core-8.0","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-router","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-server","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-server-8.0","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-server-core-8.0","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-source-8.0","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-testsuite","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"},{"name":"mysql-testsuite-8.0","version":"8.0.46-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.22.04.4","pocket":"security"}],"noble":[{"name":"mysql-8.0","version":"8.0.46-0ubuntu0.24.04.4","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"libmysqlclient21","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-client","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-client-8.0","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-client-core-8.0","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-router","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-server","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-server-8.0","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-server-core-8.0","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-source-8.0","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-testsuite","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"},{"name":"mysql-testsuite-8.0","version":"8.0.46-0ubuntu0.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.0","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.46-0ubuntu0.24.04.4","pocket":"security"}],"resolute":[{"name":"mysql-8.4","version":"8.4.11-0ubuntu0.26.04.1","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"libmysqlclient24","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"mysql-client","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"mysql-client-core","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"mysql-router","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"mysql-server","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"mysql-server-core","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"mysql-source","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"},{"name":"mysql-testsuite","version":"8.4.11-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-8.4","version_link":"https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.11-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-46936","CVE-2026-60183","CVE-2026-60585","CVE-2026-47023","CVE-2026-60331","CVE-2026-60163","CVE-2026-60315","CVE-2026-60177","CVE-2026-60184","CVE-2026-60188","CVE-2026-60316","CVE-2026-60145","CVE-2026-47052","CVE-2026-61081","CVE-2026-60332","CVE-2026-60178","CVE-2026-60187","CVE-2026-60186","CVE-2026-60190","CVE-2026-61096","CVE-2026-60182","CVE-2026-61094","CVE-2026-61109","CVE-2026-60189","CVE-2026-60747","CVE-2026-47064","CVE-2026-47012","CVE-2026-60191","CVE-2026-60185"]}]},{"id":"CVE-2026-47063","published":"2026-07-21T22:17:00","updated_at":"2026-08-31T18:11:55.478503+00:00","description":"\nVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM\nEnterprise Edition product of Oracle Java SE (component: Libraries).\nSupported versions that are affected are Oracle Java SE: 8u491, 8u491-perf,\n11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19\nand 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily\nexploitable vulnerability allows unauthenticated attacker with network\naccess via multiple protocols to compromise Oracle Java SE, Oracle GraalVM\nfor JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this\nvulnerability can result in unauthorized creation, deletion or\nmodification access to critical data or all Oracle Java SE, Oracle GraalVM\nfor JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This\nvulnerability can be exploited by using APIs in the specified Component,\ne.g., through a web service which supplies data to the APIs. This\nvulnerability also applies to Java deployments, typically in clients\nrunning sandboxed Java Web Start applications or sandboxed Java applets,\nthat load and run untrusted code (e.g., code that comes from the internet)\nand rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5\n(Integrity impacts). CVSS Vector:\n(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47063","https://openjdk.org/groups/vulnerability/advisories/2026-07-21","https://ubuntu.com/security/notices/USN-8673-1","https://ubuntu.com/security/notices/USN-8674-1","https://ubuntu.com/security/notices/USN-8676-1","https://ubuntu.com/security/notices/USN-8677-1","https://ubuntu.com/security/notices/USN-8681-1","https://ubuntu.com/security/notices/USN-8689-1","https://ubuntu.com/security/notices/USN-8693-1","https://ubuntu.com/security/notices/USN-8694-1","https://ubuntu.com/security/notices/USN-8695-1"],"bugs":[""],"patches":{"openjdk-8":[],"openjdk-9":[],"openjdk-lts":[],"openjdk-13":[],"openjdk-16":[],"openjdk-17":[],"openjdk-17-crac":[],"openjdk-18":[],"openjdk-21":[],"openjdk-21-crac":[],"openjdk-25":[],"openjdk-26":[]},"tags":{},"packages":[{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8u502-ga~us1-0ubuntu1~18.04","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"8u502-ga~us1-0ubuntu1~20.04","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"8u502-ga~us1-0ubuntu1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8u502-ga~us1-0ubuntu1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"8u502-ga~us1-0ubuntu1~26.04","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u502-ga~us1-0ubuntu1~16.04","component":null,"pocket":"esm-infra-legacy"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"no longer supported by upstream","component":null,"pocket":"security"}]},{"name":"openjdk-lts","source":"https://ubuntu.com/security/cve?package=openjdk-lts","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-lts","debian":"https://tracker.debian.org/pkg/openjdk-lts","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"11.0.32+9-1ubuntu1~18.04","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"11.0.32+9-1ubuntu1~20.04","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"11.0.32+9-1ubuntu1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"11.0.32+9-1ubuntu1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"11.0.32+9-1ubuntu1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-13","source":"https://ubuntu.com/security/cve?package=openjdk-13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-13","debian":"https://tracker.debian.org/pkg/openjdk-13","statuses":[{"release_codename":"focal","status":"ignored","description":"superseded by openjdk-17","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-16","source":"https://ubuntu.com/security/cve?package=openjdk-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-16","debian":"https://tracker.debian.org/pkg/openjdk-16","statuses":[{"release_codename":"focal","status":"ignored","description":"superseded by openjdk-17","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-17","source":"https://ubuntu.com/security/cve?package=openjdk-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-17","debian":"https://tracker.debian.org/pkg/openjdk-17","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"17.0.20+8-1~18.04","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"17.0.20+8-1~20.04","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"17.0.20+8-1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"17.0.20+8-1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"17.0.20+8-1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-17-crac","source":"https://ubuntu.com/security/cve?package=openjdk-17-crac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-17-crac","debian":"https://tracker.debian.org/pkg/openjdk-17-crac","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"17.0.20+8-0ubuntu1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-18","source":"https://ubuntu.com/security/cve?package=openjdk-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-18","debian":"https://tracker.debian.org/pkg/openjdk-18","statuses":[{"release_codename":"jammy","status":"ignored","description":"superseded by openjdk-19","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-21","source":"https://ubuntu.com/security/cve?package=openjdk-21","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-21","debian":"https://tracker.debian.org/pkg/openjdk-21","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"21.0.12+8-1~20.04","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"21.0.12+8-1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"21.0.12+8-1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"21.0.12+8-1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-21-crac","source":"https://ubuntu.com/security/cve?package=openjdk-21-crac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-21-crac","debian":"https://tracker.debian.org/pkg/openjdk-21-crac","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"21.0.12+8-0ubuntu1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-25","source":"https://ubuntu.com/security/cve?package=openjdk-25","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-25","debian":"https://tracker.debian.org/pkg/openjdk-25","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"25.0.4+7-1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"25.0.4+7-1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"25.0.4+7-1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-26","source":"https://ubuntu.com/security/cve?package=openjdk-26","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-26","debian":"https://tracker.debian.org/pkg/openjdk-26","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"26.0.2+10-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"26.0.2+10-2~26.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-8673-1","USN-8681-1","USN-8677-1","USN-8676-1","USN-8674-1","USN-8689-1","USN-8693-1","USN-8694-1","USN-8695-1"],"notices":[{"id":"USN-8673-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T13:25:30.050362","description":"It was discovered that the JSSE component of OpenJDK 8 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the ImageIO component of OpenJDK 8 did not correctly\nauthorize users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 8 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 8 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 8 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 8 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the Scripting component of OpenJDK 8 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to cause a denial of service or to read or modify sensitive data.\n(CVE-2026-47057, CVE-2026-47058)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 8 did\nnot correctly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"bionic":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~18.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"}],"xenial":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~16.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre-jamvm","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-47057","CVE-2026-60147","CVE-2026-47027","CVE-2026-41254","CVE-2026-47058","CVE-2026-47010","CVE-2026-47059","CVE-2026-47063","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8681-1","title":"OpenJDK 25 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 25.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running\nJava applications to make all the necessary changes.","references":[],"published":"2026-08-26T01:40:39.865697","description":"It was discovered that the JSSE component of OpenJDK 25 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 25 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 25 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-47063)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 25 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly use\nthis issue to cause a denial of service. (CVE-2026-41254)","is_hidden":false,"release_packages":{"jammy":[{"name":"openjdk-25","version":"25.0.4+7-1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-25-demo","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-doc","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-jdk","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-jdk-headless","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-jre","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-jre-headless","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-jre-zero","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-source","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-testsupport","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-25","version":"25.0.4+7-1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-25-demo","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-doc","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-jdk","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-jdk-headless","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-jre","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-jre-headless","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-jre-zero","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-source","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-testsupport","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-25","version":"25.0.4+7-1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-25-demo","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-doc","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-jdk","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-jdk-headless","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-jre","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-jre-headless","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-jre-zero","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-source","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-testsupport","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-47027","CVE-2026-41254","CVE-2026-47010","CVE-2026-47059","CVE-2026-46917","CVE-2026-47063","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8677-1","title":"OpenJDK 21 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 21.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T17:06:53.057126","description":"It was discovered that the JSSE component of OpenJDK 21 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 21 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 21 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 21 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 21 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 21 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 21 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the 2D (Little CMS) component of OpenJDK 21 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly use\nthis issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"focal":[{"name":"openjdk-21","version":"21.0.12+8-1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-21-demo","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-doc","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-jdk","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-jdk-headless","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-jre","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-jre-headless","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-jre-zero","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-source","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-testsupport","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"openjdk-21","version":"21.0.12+8-1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-21-demo","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-doc","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-jdk","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-jdk-headless","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-jre","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-jre-headless","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-jre-zero","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-source","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-testsupport","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-21","version":"21.0.12+8-1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-21-demo","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-doc","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-jdk","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-jdk-headless","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-jre","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-jre-headless","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-jre-zero","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-source","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-testsupport","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-21","version":"21.0.12+8-1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-21-demo","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-doc","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-jdk","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-jdk-headless","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-jre","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-jre-headless","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-jre-zero","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-source","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-testsupport","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-46917","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47063","CVE-2026-47059","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8676-1","title":"OpenJDK 17 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 17.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T16:49:57.919538","description":"It was discovered that the JSSE component of OpenJDK 17 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 17 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 17 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 17 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 17 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 17 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 17 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the 2D (Little CMS) component of OpenJDK 17 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"bionic":[{"name":"openjdk-17","version":"17.0.20+8-1~18.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-17-demo","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-doc","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jdk","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre-headless","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre-zero","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-source","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"openjdk-17","version":"17.0.20+8-1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-17-demo","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-doc","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jdk","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre-headless","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre-zero","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-source","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"openjdk-17","version":"17.0.20+8-1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-17-demo","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-doc","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-jdk","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-jre","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-jre-headless","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-jre-zero","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-source","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-17","version":"17.0.20+8-1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-17-demo","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-doc","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-jdk","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-jre","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-jre-headless","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-jre-zero","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-source","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-17","version":"17.0.20+8-1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-17-demo","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-doc","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-jdk","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-jre","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-jre-headless","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-jre-zero","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-source","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-46917","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47063","CVE-2026-47059","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8674-1","title":"OpenJDK 11 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 11.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T13:43:19.367555","description":"It was discovered that the JSSE component of OpenJDK 11 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 11 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 11 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 11 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 11 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 11 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 11 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the Scripting component of OpenJDK 11 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to cause a denial of service or to read or modify sensitive data.\n(CVE-2026-47057, CVE-2026-47058)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 11 did\nnot correctly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"bionic":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~18.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-46917","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47058","CVE-2026-47063","CVE-2026-46968","CVE-2026-47059","CVE-2026-47057","CVE-2026-47021"]},{"id":"USN-8689-1","title":"OpenJDK 26 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 26.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-31T00:41:06.626029","description":"It was discovered that the JSSE component of OpenJDK 26 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 26 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 26 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 26 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 26 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 26 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 26 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 26 did\nnot correctly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)","is_hidden":false,"release_packages":{"resolute":[{"name":"openjdk-26","version":"26.0.2+10-2~26.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-26-demo","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-doc","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-jdk","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-jdk-headless","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-jre","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-jre-headless","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-jre-zero","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-source","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-testsupport","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-46917","CVE-2026-60147","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47063","CVE-2026-47059","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8693-1","title":"CRaC JDK 17 vulnerabilities","summary":"Several security issues were fixed in CRaC JDK 17.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-31T10:33:52.676296","description":"It was discovered that the JSSE component of CRaC JDK 17 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of CRaC JDK 17 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of CRaC JDK 17 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of CRaC JDK 17 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of CRaC JDK 17 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of CRaC JDK 17 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of CRaC JDK 17 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the 2D (Little CMS) component of CRaC JDK 17 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"resolute":[{"name":"openjdk-17-crac","version":"17.0.20+8-0ubuntu1~26.04","description":"Open Source Java implementation with Coordinated Restore at Checkpoints","is_source":true},{"name":"openjdk-17-crac-demo","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-doc","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-jdk","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-jdk-headless","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-jre","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-jre-headless","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-jre-zero","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-source","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-46917","CVE-2026-60147","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47063","CVE-2026-47059","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8694-1","title":"CRaC JDK 21 vulnerabilities","summary":"Several security issues were fixed in CRaC JDK 21.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-31T10:38:07.326530","description":"It was discovered that the JSSE component of CRaC JDK 21 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of CRaC JDK 21 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of CRaC JDK 21 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of CRaC JDK 21 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of CRaC JDK 21 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of CRaC JDK 21 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of CRaC JDK 21 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the 2D (Little CMS) component of CRaC JDK 21 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"resolute":[{"name":"openjdk-21-crac","version":"21.0.12+8-0ubuntu1~26.04","description":"Open Source Java implementation with Coordinated Restore at Checkpoints","is_source":true},{"name":"openjdk-21-crac-demo","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-doc","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-jdk","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-jdk-headless","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-jre","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-jre-headless","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-jre-zero","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-source","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-testsupport","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-46917","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47063","CVE-2026-47059","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8695-1","title":"CRaC JDK 25 vulnerabilities","summary":"Several security issues were fixed in CRaC JDK 25.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-31T10:43:21.840556","description":"It was discovered that the JSSE component of CRaC JDK 25 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of CRaC JDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of CRaC JDK 25 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of CRaC JDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of CRaC JDK 25 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of CRaC JDK 25 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of CRaC JDK 25 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the 2D (Little CMS) component of CRaC JDK 25 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"resolute":[{"name":"openjdk-25-crac","version":"25.0.4+7-0ubuntu1~26.04","description":"Open Source Java implementation with Coordinated Restore at Checkpoints","is_source":true},{"name":"openjdk-25-crac-demo","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-doc","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-jdk","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-jdk-headless","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-jre","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-jre-headless","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-jre-zero","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-source","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-testsupport","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-47027","CVE-2026-41254","CVE-2026-47010","CVE-2026-47059","CVE-2026-46917","CVE-2026-47063","CVE-2026-46968","CVE-2026-47021"]}]},{"id":"CVE-2026-47062","published":"2026-07-21T22:17:00","updated_at":"2026-08-06T23:45:46.767884+00:00","description":"\nVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization\n(component: Core). The supported version that is affected is 7.2.12.\nEasily exploitable vulnerability allows low privileged attacker with logon\nto the infrastructure where Oracle VM VirtualBox executes to compromise\nOracle VM VirtualBox. Successful attacks of this vulnerability can result\nin unauthorized ability to cause a hang or frequently repeatable crash\n(complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.5\n(Availability impacts). CVSS Vector:\n(CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47062"],"bugs":[""],"patches":{"virtualbox":[]},"tags":{},"packages":[{"name":"virtualbox","source":"https://ubuntu.com/security/cve?package=virtualbox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=virtualbox","debian":"https://tracker.debian.org/pkg/virtualbox","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47059","published":"2026-07-21T22:17:00","updated_at":"2026-08-31T18:11:33.128559+00:00","description":"\nVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM\nEnterprise Edition product of Oracle Java SE (component: 2D). Supported\nversions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31,\n17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and\n21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit\nvulnerability allows unauthenticated attacker with network access via\nmultiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK,\nOracle GraalVM Enterprise Edition. Successful attacks of this\nvulnerability can result in unauthorized ability to cause a partial denial\nof service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle\nGraalVM Enterprise Edition. Note: This vulnerability applies to Java\ndeployments, typically in clients running sandboxed Java Web Start\napplications or sandboxed Java applets, that load and run untrusted code\n(e.g., code that comes from the internet) and rely on the Java sandbox for\nsecurity. This vulnerability does not apply to Java deployments, typically\nin servers, that load and run only trusted code (e.g., code installed by an\nadministrator). CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS\nVector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47059","https://openjdk.org/groups/vulnerability/advisories/2026-07-21","https://ubuntu.com/security/notices/USN-8673-1","https://ubuntu.com/security/notices/USN-8674-1","https://ubuntu.com/security/notices/USN-8676-1","https://ubuntu.com/security/notices/USN-8677-1","https://ubuntu.com/security/notices/USN-8681-1","https://ubuntu.com/security/notices/USN-8689-1","https://ubuntu.com/security/notices/USN-8693-1","https://ubuntu.com/security/notices/USN-8694-1","https://ubuntu.com/security/notices/USN-8695-1"],"bugs":[""],"patches":{"openjdk-8":[],"openjdk-9":[],"openjdk-lts":[],"openjdk-13":[],"openjdk-16":[],"openjdk-17":[],"openjdk-17-crac":[],"openjdk-18":[],"openjdk-21":[],"openjdk-21-crac":[],"openjdk-25":[],"openjdk-26":[]},"tags":{},"packages":[{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8u502-ga~us1-0ubuntu1~18.04","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"8u502-ga~us1-0ubuntu1~20.04","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"8u502-ga~us1-0ubuntu1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8u502-ga~us1-0ubuntu1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"8u502-ga~us1-0ubuntu1~26.04","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u502-ga~us1-0ubuntu1~16.04","component":null,"pocket":"esm-infra-legacy"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"no longer supported by upstream","component":null,"pocket":"security"}]},{"name":"openjdk-lts","source":"https://ubuntu.com/security/cve?package=openjdk-lts","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-lts","debian":"https://tracker.debian.org/pkg/openjdk-lts","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"11.0.32+9-1ubuntu1~18.04","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"11.0.32+9-1ubuntu1~20.04","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"11.0.32+9-1ubuntu1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"11.0.32+9-1ubuntu1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"11.0.32+9-1ubuntu1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-13","source":"https://ubuntu.com/security/cve?package=openjdk-13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-13","debian":"https://tracker.debian.org/pkg/openjdk-13","statuses":[{"release_codename":"focal","status":"ignored","description":"superseded by openjdk-17","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-16","source":"https://ubuntu.com/security/cve?package=openjdk-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-16","debian":"https://tracker.debian.org/pkg/openjdk-16","statuses":[{"release_codename":"focal","status":"ignored","description":"superseded by openjdk-17","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-17","source":"https://ubuntu.com/security/cve?package=openjdk-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-17","debian":"https://tracker.debian.org/pkg/openjdk-17","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"17.0.20+8-1~18.04","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"17.0.20+8-1~20.04","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"17.0.20+8-1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"17.0.20+8-1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"17.0.20+8-1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-17-crac","source":"https://ubuntu.com/security/cve?package=openjdk-17-crac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-17-crac","debian":"https://tracker.debian.org/pkg/openjdk-17-crac","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"17.0.20+8-0ubuntu1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-18","source":"https://ubuntu.com/security/cve?package=openjdk-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-18","debian":"https://tracker.debian.org/pkg/openjdk-18","statuses":[{"release_codename":"jammy","status":"ignored","description":"superseded by openjdk-19","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-21","source":"https://ubuntu.com/security/cve?package=openjdk-21","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-21","debian":"https://tracker.debian.org/pkg/openjdk-21","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"21.0.12+8-1~20.04","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"21.0.12+8-1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"21.0.12+8-1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"21.0.12+8-1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-21-crac","source":"https://ubuntu.com/security/cve?package=openjdk-21-crac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-21-crac","debian":"https://tracker.debian.org/pkg/openjdk-21-crac","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"21.0.12+8-0ubuntu1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-25","source":"https://ubuntu.com/security/cve?package=openjdk-25","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-25","debian":"https://tracker.debian.org/pkg/openjdk-25","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"25.0.4+7-1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"25.0.4+7-1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"25.0.4+7-1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-26","source":"https://ubuntu.com/security/cve?package=openjdk-26","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-26","debian":"https://tracker.debian.org/pkg/openjdk-26","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"26.0.2+10-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"26.0.2+10-2~26.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-8673-1","USN-8681-1","USN-8677-1","USN-8676-1","USN-8674-1","USN-8689-1","USN-8693-1","USN-8694-1","USN-8695-1"],"notices":[{"id":"USN-8673-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T13:25:30.050362","description":"It was discovered that the JSSE component of OpenJDK 8 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the ImageIO component of OpenJDK 8 did not correctly\nauthorize users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 8 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 8 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 8 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 8 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the Scripting component of OpenJDK 8 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to cause a denial of service or to read or modify sensitive data.\n(CVE-2026-47057, CVE-2026-47058)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 8 did\nnot correctly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"bionic":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~18.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"}],"xenial":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~16.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre-jamvm","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-47057","CVE-2026-60147","CVE-2026-47027","CVE-2026-41254","CVE-2026-47058","CVE-2026-47010","CVE-2026-47059","CVE-2026-47063","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8681-1","title":"OpenJDK 25 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 25.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running\nJava applications to make all the necessary changes.","references":[],"published":"2026-08-26T01:40:39.865697","description":"It was discovered that the JSSE component of OpenJDK 25 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 25 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 25 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-47063)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 25 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly use\nthis issue to cause a denial of service. (CVE-2026-41254)","is_hidden":false,"release_packages":{"jammy":[{"name":"openjdk-25","version":"25.0.4+7-1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-25-demo","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-doc","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-jdk","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-jdk-headless","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-jre","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-jre-headless","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-jre-zero","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-source","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"},{"name":"openjdk-25-testsupport","version":"25.0.4+7-1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-25","version":"25.0.4+7-1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-25-demo","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-doc","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-jdk","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-jdk-headless","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-jre","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-jre-headless","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-jre-zero","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-source","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"},{"name":"openjdk-25-testsupport","version":"25.0.4+7-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-25","version":"25.0.4+7-1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-25-demo","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-doc","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-jdk","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-jdk-headless","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-jre","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-jre-headless","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-jre-zero","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-source","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"},{"name":"openjdk-25-testsupport","version":"25.0.4+7-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25/25.0.4+7-1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-47027","CVE-2026-41254","CVE-2026-47010","CVE-2026-47059","CVE-2026-46917","CVE-2026-47063","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8677-1","title":"OpenJDK 21 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 21.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T17:06:53.057126","description":"It was discovered that the JSSE component of OpenJDK 21 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 21 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 21 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 21 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 21 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 21 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 21 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the 2D (Little CMS) component of OpenJDK 21 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly use\nthis issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"focal":[{"name":"openjdk-21","version":"21.0.12+8-1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-21-demo","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-doc","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-jdk","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-jdk-headless","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-jre","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-jre-headless","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-jre-zero","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-source","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-21-testsupport","version":"21.0.12+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"openjdk-21","version":"21.0.12+8-1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-21-demo","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-doc","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-jdk","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-jdk-headless","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-jre","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-jre-headless","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-jre-zero","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-source","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"},{"name":"openjdk-21-testsupport","version":"21.0.12+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-21","version":"21.0.12+8-1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-21-demo","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-doc","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-jdk","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-jdk-headless","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-jre","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-jre-headless","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-jre-zero","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-source","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"},{"name":"openjdk-21-testsupport","version":"21.0.12+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-21","version":"21.0.12+8-1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-21-demo","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-doc","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-jdk","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-jdk-headless","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-jre","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-jre-headless","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-jre-zero","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-source","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"},{"name":"openjdk-21-testsupport","version":"21.0.12+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21/21.0.12+8-1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-46917","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47063","CVE-2026-47059","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8676-1","title":"OpenJDK 17 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 17.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T16:49:57.919538","description":"It was discovered that the JSSE component of OpenJDK 17 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 17 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 17 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 17 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 17 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 17 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 17 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the 2D (Little CMS) component of OpenJDK 17 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"bionic":[{"name":"openjdk-17","version":"17.0.20+8-1~18.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-17-demo","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-doc","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jdk","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre-headless","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre-zero","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-source","version":"17.0.20+8-1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"openjdk-17","version":"17.0.20+8-1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-17-demo","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-doc","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jdk","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre-headless","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-jre-zero","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-17-source","version":"17.0.20+8-1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"openjdk-17","version":"17.0.20+8-1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-17-demo","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-doc","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-jdk","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-jre","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-jre-headless","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-jre-zero","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"},{"name":"openjdk-17-source","version":"17.0.20+8-1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-17","version":"17.0.20+8-1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-17-demo","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-doc","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-jdk","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-jre","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-jre-headless","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-jre-zero","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"},{"name":"openjdk-17-source","version":"17.0.20+8-1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-17","version":"17.0.20+8-1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-17-demo","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-doc","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-jdk","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-jdk-headless","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-jre","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-jre-headless","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-jre-zero","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"},{"name":"openjdk-17-source","version":"17.0.20+8-1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17/17.0.20+8-1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-46917","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47063","CVE-2026-47059","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8674-1","title":"OpenJDK 11 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 11.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T13:43:19.367555","description":"It was discovered that the JSSE component of OpenJDK 11 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 11 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 11 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 11 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 11 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 11 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 11 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the Scripting component of OpenJDK 11 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to cause a denial of service or to read or modify sensitive data.\n(CVE-2026-47057, CVE-2026-47058)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 11 did\nnot correctly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"bionic":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~18.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-46917","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47058","CVE-2026-47063","CVE-2026-46968","CVE-2026-47059","CVE-2026-47057","CVE-2026-47021"]},{"id":"USN-8689-1","title":"OpenJDK 26 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 26.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-31T00:41:06.626029","description":"It was discovered that the JSSE component of OpenJDK 26 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 26 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 26 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 26 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 26 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 26 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 26 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 26 did\nnot correctly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)","is_hidden":false,"release_packages":{"resolute":[{"name":"openjdk-26","version":"26.0.2+10-2~26.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-26-demo","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-doc","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-jdk","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-jdk-headless","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-jre","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-jre-headless","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-jre-zero","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-source","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"},{"name":"openjdk-26-testsupport","version":"26.0.2+10-2~26.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-26","version_link":"https://launchpad.net/ubuntu/+source/openjdk-26/26.0.2+10-2~26.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-46917","CVE-2026-60147","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47063","CVE-2026-47059","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8693-1","title":"CRaC JDK 17 vulnerabilities","summary":"Several security issues were fixed in CRaC JDK 17.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-31T10:33:52.676296","description":"It was discovered that the JSSE component of CRaC JDK 17 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of CRaC JDK 17 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of CRaC JDK 17 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of CRaC JDK 17 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of CRaC JDK 17 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of CRaC JDK 17 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of CRaC JDK 17 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the 2D (Little CMS) component of CRaC JDK 17 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"resolute":[{"name":"openjdk-17-crac","version":"17.0.20+8-0ubuntu1~26.04","description":"Open Source Java implementation with Coordinated Restore at Checkpoints","is_source":true},{"name":"openjdk-17-crac-demo","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-doc","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-jdk","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-jdk-headless","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-jre","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-jre-headless","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-jre-zero","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-17-crac-source","version":"17.0.20+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-17-crac/17.0.20+8-0ubuntu1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-46917","CVE-2026-60147","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47063","CVE-2026-47059","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8694-1","title":"CRaC JDK 21 vulnerabilities","summary":"Several security issues were fixed in CRaC JDK 21.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-31T10:38:07.326530","description":"It was discovered that the JSSE component of CRaC JDK 21 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of CRaC JDK 21 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of CRaC JDK 21 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of CRaC JDK 21 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of CRaC JDK 21 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of CRaC JDK 21 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of CRaC JDK 21 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the 2D (Little CMS) component of CRaC JDK 21 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"resolute":[{"name":"openjdk-21-crac","version":"21.0.12+8-0ubuntu1~26.04","description":"Open Source Java implementation with Coordinated Restore at Checkpoints","is_source":true},{"name":"openjdk-21-crac-demo","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-doc","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-jdk","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-jdk-headless","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-jre","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-jre-headless","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-jre-zero","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-source","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-21-crac-testsupport","version":"21.0.12+8-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-21-crac/21.0.12+8-0ubuntu1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-46917","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47063","CVE-2026-47059","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8695-1","title":"CRaC JDK 25 vulnerabilities","summary":"Several security issues were fixed in CRaC JDK 25.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-31T10:43:21.840556","description":"It was discovered that the JSSE component of CRaC JDK 25 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of CRaC JDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of CRaC JDK 25 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of CRaC JDK 25 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of CRaC JDK 25 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of CRaC JDK 25 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of CRaC JDK 25 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the 2D (Little CMS) component of CRaC JDK 25 did not\ncorrectly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"resolute":[{"name":"openjdk-25-crac","version":"25.0.4+7-0ubuntu1~26.04","description":"Open Source Java implementation with Coordinated Restore at Checkpoints","is_source":true},{"name":"openjdk-25-crac-demo","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-doc","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-jdk","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-jdk-headless","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-jre","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-jre-headless","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-jre-zero","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-source","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-25-crac-testsupport","version":"25.0.4+7-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac","version_link":"https://launchpad.net/ubuntu/+source/openjdk-25-crac/25.0.4+7-0ubuntu1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-47027","CVE-2026-41254","CVE-2026-47010","CVE-2026-47059","CVE-2026-46917","CVE-2026-47063","CVE-2026-46968","CVE-2026-47021"]}]},{"id":"CVE-2026-47058","published":"2026-07-21T22:17:00","updated_at":"2026-08-26T11:44:56.398250+00:00","description":"\nVulnerability in Oracle Java SE (component: Scripting). Supported versions\nthat are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31.\nDifficult to exploit vulnerability allows unauthenticated attacker with\nnetwork access via multiple protocols to compromise Oracle Java SE.\nSuccessful attacks of this vulnerability can result in unauthorized\ncreation, deletion or modification access to critical data or all Oracle\nJava SE accessible data as well as unauthorized access to critical data or\ncomplete access to all Oracle Java SE accessible data. Note: This\nvulnerability can be exploited by using APIs in the specified Component,\ne.g., through a web service which supplies data to the APIs. This\nvulnerability also applies to Java deployments, typically in clients\nrunning sandboxed Java Web Start applications or sandboxed Java applets,\nthat load and run untrusted code (e.g., code that comes from the internet)\nand rely on the Java sandbox for security. CVSS 3.1 Base Score 7.4\n(Confidentiality and Integrity impacts). CVSS Vector:\n(CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47058","https://openjdk.org/groups/vulnerability/advisories/2026-07-21","https://ubuntu.com/security/notices/USN-8673-1","https://ubuntu.com/security/notices/USN-8674-1"],"bugs":[""],"patches":{"openjdk-8":[],"openjdk-9":[],"openjdk-lts":[],"openjdk-13":[],"openjdk-16":[],"openjdk-17":[],"openjdk-17-crac":[],"openjdk-18":[],"openjdk-21":[],"openjdk-21-crac":[],"openjdk-25":[]},"tags":{},"packages":[{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8u502-ga~us1-0ubuntu1~18.04","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"8u502-ga~us1-0ubuntu1~20.04","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"8u502-ga~us1-0ubuntu1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8u502-ga~us1-0ubuntu1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"8u502-ga~us1-0ubuntu1~26.04","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u502-ga~us1-0ubuntu1~16.04","component":null,"pocket":"esm-infra-legacy"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"no longer supported by upstream","component":null,"pocket":"security"}]},{"name":"openjdk-lts","source":"https://ubuntu.com/security/cve?package=openjdk-lts","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-lts","debian":"https://tracker.debian.org/pkg/openjdk-lts","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"11.0.32+9-1ubuntu1~18.04","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"11.0.32+9-1ubuntu1~20.04","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"11.0.32+9-1ubuntu1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"11.0.32+9-1ubuntu1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"11.0.32+9-1ubuntu1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-13","source":"https://ubuntu.com/security/cve?package=openjdk-13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-13","debian":"https://tracker.debian.org/pkg/openjdk-13","statuses":[{"release_codename":"focal","status":"ignored","description":"superseded by openjdk-17","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-16","source":"https://ubuntu.com/security/cve?package=openjdk-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-16","debian":"https://tracker.debian.org/pkg/openjdk-16","statuses":[{"release_codename":"focal","status":"ignored","description":"superseded by openjdk-17","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-17","source":"https://ubuntu.com/security/cve?package=openjdk-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-17","debian":"https://tracker.debian.org/pkg/openjdk-17","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-17-crac","source":"https://ubuntu.com/security/cve?package=openjdk-17-crac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-17-crac","debian":"https://tracker.debian.org/pkg/openjdk-17-crac","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-18","source":"https://ubuntu.com/security/cve?package=openjdk-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-18","debian":"https://tracker.debian.org/pkg/openjdk-18","statuses":[{"release_codename":"jammy","status":"ignored","description":"superseded by openjdk-19","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-21","source":"https://ubuntu.com/security/cve?package=openjdk-21","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-21","debian":"https://tracker.debian.org/pkg/openjdk-21","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-21-crac","source":"https://ubuntu.com/security/cve?package=openjdk-21-crac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-21-crac","debian":"https://tracker.debian.org/pkg/openjdk-21-crac","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-25","source":"https://ubuntu.com/security/cve?package=openjdk-25","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-25","debian":"https://tracker.debian.org/pkg/openjdk-25","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8673-1","USN-8674-1"],"notices":[{"id":"USN-8673-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T13:25:30.050362","description":"It was discovered that the JSSE component of OpenJDK 8 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the ImageIO component of OpenJDK 8 did not correctly\nauthorize users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 8 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 8 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 8 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 8 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the Scripting component of OpenJDK 8 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to cause a denial of service or to read or modify sensitive data.\n(CVE-2026-47057, CVE-2026-47058)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 8 did\nnot correctly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"bionic":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~18.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"}],"xenial":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~16.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre-jamvm","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-47057","CVE-2026-60147","CVE-2026-47027","CVE-2026-41254","CVE-2026-47058","CVE-2026-47010","CVE-2026-47059","CVE-2026-47063","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8674-1","title":"OpenJDK 11 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 11.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T13:43:19.367555","description":"It was discovered that the JSSE component of OpenJDK 11 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 11 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 11 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 11 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 11 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 11 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 11 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the Scripting component of OpenJDK 11 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to cause a denial of service or to read or modify sensitive data.\n(CVE-2026-47057, CVE-2026-47058)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 11 did\nnot correctly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"bionic":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~18.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-46917","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47058","CVE-2026-47063","CVE-2026-46968","CVE-2026-47059","CVE-2026-47057","CVE-2026-47021"]}]},{"id":"CVE-2026-47057","published":"2026-07-21T22:17:00","updated_at":"2026-08-26T11:44:56.398250+00:00","description":"\nVulnerability in Oracle Java SE (component: Scripting). Supported versions\nthat are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31.\nEasily exploitable vulnerability allows unauthenticated attacker with\nnetwork access via multiple protocols to compromise Oracle Java SE.\nSuccessful attacks of this vulnerability can result in unauthorized ability\nto cause a hang or frequently repeatable crash (complete DOS) of Oracle\nJava SE. Note: This vulnerability can be exploited by using APIs in the\nspecified Component, e.g., through a web service which supplies data to the\nAPIs. This vulnerability also applies to Java deployments, typically in\nclients running sandboxed Java Web Start applications or sandboxed Java\napplets, that load and run untrusted code (e.g., code that comes from the\ninternet) and rely on the Java sandbox for security. CVSS 3.1 Base Score\n7.5 (Availability impacts). CVSS Vector:\n(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47057","https://openjdk.org/groups/vulnerability/advisories/2026-07-21","https://ubuntu.com/security/notices/USN-8673-1","https://ubuntu.com/security/notices/USN-8674-1"],"bugs":[""],"patches":{"openjdk-8":[],"openjdk-9":[],"openjdk-lts":[],"openjdk-13":[],"openjdk-16":[],"openjdk-17":[],"openjdk-17-crac":[],"openjdk-18":[],"openjdk-21":[],"openjdk-21-crac":[],"openjdk-25":[]},"tags":{},"packages":[{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8u502-ga~us1-0ubuntu1~18.04","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"8u502-ga~us1-0ubuntu1~20.04","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"8u502-ga~us1-0ubuntu1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8u502-ga~us1-0ubuntu1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"8u502-ga~us1-0ubuntu1~26.04","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u502-ga~us1-0ubuntu1~16.04","component":null,"pocket":"esm-infra-legacy"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"no longer supported by upstream","component":null,"pocket":"security"}]},{"name":"openjdk-lts","source":"https://ubuntu.com/security/cve?package=openjdk-lts","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-lts","debian":"https://tracker.debian.org/pkg/openjdk-lts","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"11.0.32+9-1ubuntu1~18.04","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"11.0.32+9-1ubuntu1~20.04","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"11.0.32+9-1ubuntu1~22.04","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"11.0.32+9-1ubuntu1~24.04","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"11.0.32+9-1ubuntu1~26.04","component":null,"pocket":"security"}]},{"name":"openjdk-13","source":"https://ubuntu.com/security/cve?package=openjdk-13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-13","debian":"https://tracker.debian.org/pkg/openjdk-13","statuses":[{"release_codename":"focal","status":"ignored","description":"superseded by openjdk-17","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-16","source":"https://ubuntu.com/security/cve?package=openjdk-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-16","debian":"https://tracker.debian.org/pkg/openjdk-16","statuses":[{"release_codename":"focal","status":"ignored","description":"superseded by openjdk-17","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-17","source":"https://ubuntu.com/security/cve?package=openjdk-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-17","debian":"https://tracker.debian.org/pkg/openjdk-17","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-17-crac","source":"https://ubuntu.com/security/cve?package=openjdk-17-crac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-17-crac","debian":"https://tracker.debian.org/pkg/openjdk-17-crac","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-18","source":"https://ubuntu.com/security/cve?package=openjdk-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-18","debian":"https://tracker.debian.org/pkg/openjdk-18","statuses":[{"release_codename":"jammy","status":"ignored","description":"superseded by openjdk-19","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-21","source":"https://ubuntu.com/security/cve?package=openjdk-21","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-21","debian":"https://tracker.debian.org/pkg/openjdk-21","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-21-crac","source":"https://ubuntu.com/security/cve?package=openjdk-21-crac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-21-crac","debian":"https://tracker.debian.org/pkg/openjdk-21-crac","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-25","source":"https://ubuntu.com/security/cve?package=openjdk-25","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-25","debian":"https://tracker.debian.org/pkg/openjdk-25","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8673-1","USN-8674-1"],"notices":[{"id":"USN-8673-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T13:25:30.050362","description":"It was discovered that the JSSE component of OpenJDK 8 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the ImageIO component of OpenJDK 8 did not correctly\nauthorize users. A remote attacker could possibly use this issue to read or\nmodify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 8 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 8 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 8 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 8 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the Scripting component of OpenJDK 8 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to cause a denial of service or to read or modify sensitive data.\n(CVE-2026-47057, CVE-2026-47058)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 8 did\nnot correctly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"bionic":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~18.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u502-ga~us1-0ubuntu1~26.04","pocket":"security"}],"xenial":[{"name":"openjdk-8","version":"8u502-ga~us1-0ubuntu1~16.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-doc","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jdk","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jdk-headless","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre-headless","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre-jamvm","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-jre-zero","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openjdk-8-source","version":"8u502-ga~us1-0ubuntu1~16.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-47057","CVE-2026-60147","CVE-2026-47027","CVE-2026-41254","CVE-2026-47058","CVE-2026-47010","CVE-2026-47059","CVE-2026-47063","CVE-2026-46968","CVE-2026-47021"]},{"id":"USN-8674-1","title":"OpenJDK 11 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 11.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any running Java\napplications to make all the necessary changes.","references":[],"published":"2026-08-25T13:43:19.367555","description":"It was discovered that the JSSE component of OpenJDK 11 did not correctly\nauthenticate users. A remote attacker could possibly use this issue to read\nor modify sensitive data. (CVE-2026-46968)\n\nIt was discovered that the JSSE component of OpenJDK 11 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-46917)\n\nIt was discovered that the ImageIO component of OpenJDK 11 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto read or modify sensitive data. (CVE-2026-47010)\n\nIt was discovered that the 2D component of OpenJDK 11 did not correctly\nauthorize users. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-47021, CVE-2026-47059)\n\nIt was discovered that the Libraries component of OpenJDK 11 did not\ncorrectly authorize users. A remote attacker could possibly use this issue\nto cause a denial of service. (CVE-2026-47027)\n\nIt was discovered that the Security component of OpenJDK 11 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-60147)\n\nIt was discovered that the Libraries component of OpenJDK 11 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to read or modify sensitive data. (CVE-2026-47063)\n\nIt was discovered that the Scripting component of OpenJDK 11 did not\ncorrectly authenticate users. A remote attacker could possibly use this\nissue to cause a denial of service or to read or modify sensitive data.\n(CVE-2026-47057, CVE-2026-47058)\n\nLian Owen discovered that the 2D (Little CMS) component of OpenJDK 11 did\nnot correctly handle certain integer arithmetic. An attacker could possibly\nuse this issue to cause a denial of service. (CVE-2026-41254)\n\nIn addition to security fixes, the updated packages contain bug fixes, new\nfeatures, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2026-07-21","is_hidden":false,"release_packages":{"bionic":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~18.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~20.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~22.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~22.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~22.04","pocket":"security"}],"noble":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~24.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~24.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~24.04","pocket":"security"}],"resolute":[{"name":"openjdk-lts","version":"11.0.32+9-1ubuntu1~26.04","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-11-demo","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-doc","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jdk","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jdk-headless","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jre","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jre-headless","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-jre-zero","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"},{"name":"openjdk-11-source","version":"11.0.32+9-1ubuntu1~26.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-lts","version_link":"https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.32+9-1ubuntu1~26.04","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-60147","CVE-2026-46917","CVE-2026-47010","CVE-2026-41254","CVE-2026-47027","CVE-2026-47058","CVE-2026-47063","CVE-2026-46968","CVE-2026-47059","CVE-2026-47057","CVE-2026-47021"]}]}],"offset":6880,"limit":20,"total_results":79316}