Opened 8 months ago
Closed 7 months ago
#22669 closed enhancement (fixed)
OpenJDK-21.0.10
| Reported by: | zeckma | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point release.
This is a security release.
Change History (8)
comment:1 by , 8 months ago
comment:2 by , 8 months ago
Security fixes
- CVE-2026-21925 (Medium): Unauthorized update, insert, or delete access of Java data (network access with multiple protocols)
- CVE-2026-21932 (High): Unauthorized creation, deletion or modification access to critical data (network access with multiple protocols)
- CVE-2026-21933 (Medium): Unauthorized update, insert, or delete access of Java data (network access with multiple protocols, req. human interaction)
- CVE-2026-21945 (High): Denial of service (DOS) (network access with multiple protocols)
comment:4 by , 8 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:5 by , 8 months ago
| Priority: | elevated → high |
|---|
comment:6 by , 8 months ago
A new notice has been posted to the Oracle Critical Patch Update Advisory page:
Oracle continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches. In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply Critical Patch Update security patches without delay.
comment:7 by , 7 months ago
Pierre has noted that the existing binary seems to be broken, where it can execute code but is unable to compile any. Not sure what's going on with that, will investigate when I get to JDK...
comment:8 by , 7 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at 6dc60c609dd128fe6e2279285320fdf5b9081db6
SA-12.4-112 issued

Oracle advisory: https://www.oracle.com/security-alerts/cpujan2026.html#AppendixJAVA