Opened 5 months ago

Closed 5 weeks ago

Last modified 5 weeks ago

#23218 closed enhancement (fixed)

jdk-21.0.12.1

Reported by: Douglas R. Reno Owned by: SecurityAdvisory
Priority: high Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New quarterly OpenJDK release.

This includes fixes for the following security vulnerabilities:

  • CVE-2026-22016 in the JAXP component. Rated as 7.5 High, low attack complexity and no privileges required. It is remotely exploitable and allows for trivial remote access to any information that the Java process is able to access.
  • CVE-2026-34282 in the Networking component. Rated as 7.5 High, low attack complexity and no privileges required. It is remotely exploitable and allows for easy crashes of Java applications.
  • CVE-2026-22021 in the JSSE component. Rated as 5.3 Medium. Remotely exploitable with low attack complexity and no privileges required. It allows for easy crashes of Java applications.
  • CVE-2026-22013 in the JGSS component. Rated as 5.3 Medium. Remotely exploitable with no privileges required, but the vulnerability is complex to exploit. Successful exploitation though allows for remote access to any information that the Java process is able to access.
  • CVE-2026-23865 in the 2D (Freetype) component. Rated as 5.3 Medium. Only exploitable locally and allows for a malicious font in a Java program to cause denial of service, and a low chance of information disclosure or arbitrary code execution.
  • CVE-2026-22018 in the Libraries component. Rated as 3.7 Low. Remotely exploitable vulnerability with High attack complexity and no privileges required. It allows for a remote attacker to crash a Java program.
  • CVE-2026-22007 in the Security component. Rated as 2.9 Low. Local attackers can possibly access all information on a system that a Java process can access without any privileges required or user interaction.
  • CVE-2026-34628 in the Security component. Rated as 2.9 Low. Local attackers can possibly access all information on a system that a Java process can access without any privileges required or user interaction.

Note that of the above vulnerabilities, only the FreeType and the JGSS issues require any user interaction to successfully exploit.

Change History (10)

comment:1 by Douglas R. Reno, 5 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:2 by Douglas R. Reno, 4 months ago

Owner: changed from Douglas R. Reno to blfs-book
Status: assigned → new

I'm going to reassign these to the book for now so whoever wants to do them can do them.

In the meantime I will continue working on rivendell, but I do not want to continue holding the project back on important issues.

comment:3 by Douglas R. Reno, 4 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:4 by pierre, 6 weeks ago

Taking those for 13.1 release, as Doug cannot do them by lack of time.

comment:5 by pierre, 6 weeks ago

Owner: changed from Douglas R. Reno to pierre
Status: assigned → new

comment:6 by pierre, 5 weeks ago

Summary: jdk-21.0.11 → jdk-21.0.12.1

Now jdk-21.0.12.1

(build 1)

comment:7 by Bruce Dubbs, 5 weeks ago

Owner: changed from pierre to SecurityAdvisory

Updated at commit c1a60c3603. Leaving open for SA.

comment:8 by Bruce Dubbs, 5 weeks ago

Milestone: 13.1 → 98-Security

comment:9 by Bruce Dubbs, 5 weeks ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-211 has been issued.

comment:10 by pierre, 5 weeks ago

There are more security fixes in 21.0.12:

  • CVE-2026-41254 in the 2D component (little CMS), rated as high (7.5). Low attack complexity and no privileges required. Not affecting us, since we use system littleCMS.
  • CVE-2026-47063 in libraries, rated as high (7.5). Low attack complexity and no privileges required.
  • CVE-2026-60147 in the security component, rated as medium (6.5). Low attack complexity and no privileges required.
  • CVE-2026-46968 in the JSSE component, rated as medium (5.9). High attack complexity and no privileges required
  • CVE-2026-47027 in libraries, rated as medium (5.3). Low attack complexity and no privileges required.
  • CVE-2026-47021 in the 2D component, rated as medium (5.3). Low attack complexity and no privileges required.
  • CVE-2026-46917 in the JSSE component, rated as medium (5.3). Low attack complexity and no privileges required.
  • CVE-2026-47059 in the 2D component, rated as medium (5.9). High attack complexity and no privileges required.
  • CVE-2026-47010 in the ImageIO component, rated as low (3.7). High attack complexity and no privileges required.

See nvd site for details.

Note: See TracTickets for help on using tickets.