Opened 11 months ago

Closed 9 months ago

Last modified 8 months ago

#22347 closed enhancement (fixed)

jdk-21.0.9 (downgrade for security reasons)

Reported by: Douglas R. Reno Owned by: Douglas R. Reno
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version

At the moment due to the high severity security issues in JDK that are under active exploitation, it is a good idea to downgrade to 21.0.9. The reason why we aren't going to 25 yet is that there are several unfixed bugs that were not resolved in 25.0.1, which cause existing applications to no longer run and major problems with XML SAX support which cause programs such as fop, ant, maven, etc. to not build or run.

Downgrading to this LTS version is definitely the best approach for now. We can re-examine 25 when it's more stable, especially as it's the next LTS.

Vulnerabilities fixed in this release:

  • CVE-2025-53066 - in the JAXP component. Actively exploited. Remotely exploitable without authentication or interaction, low attack complexity, and high confidentiality impact. With my Minecraft servers, this includes attackers trying to read /etc/passwd and other critical system information.
  • CVE-2025-53057 - in the Security component. Remotely exploitable without user authentication or interaction, rated as Medium with high attack complexity.
  • CVE-2025-61748 - in the Libraries component. Remotely exploitable without authentication, rated as Low with High attack complexity.

Change History (3)

comment:1 by Douglas R. Reno, 11 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:2 by Douglas R. Reno, 9 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at fcac90e8e4c73e9f2cd42ce512ae73c303396f5c

SA-12.4-067 issued

comment:3 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.