#23218 closed enhancement (fixed)
jdk-21.0.12.1
| Reported by: | Douglas R. Reno | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New quarterly OpenJDK release.
This includes fixes for the following security vulnerabilities:
- CVE-2026-22016 in the JAXP component. Rated as 7.5 High, low attack complexity and no privileges required. It is remotely exploitable and allows for trivial remote access to any information that the Java process is able to access.
- CVE-2026-34282 in the Networking component. Rated as 7.5 High, low attack complexity and no privileges required. It is remotely exploitable and allows for easy crashes of Java applications.
- CVE-2026-22021 in the JSSE component. Rated as 5.3 Medium. Remotely exploitable with low attack complexity and no privileges required. It allows for easy crashes of Java applications.
- CVE-2026-22013 in the JGSS component. Rated as 5.3 Medium. Remotely exploitable with no privileges required, but the vulnerability is complex to exploit. Successful exploitation though allows for remote access to any information that the Java process is able to access.
- CVE-2026-23865 in the 2D (Freetype) component. Rated as 5.3 Medium. Only exploitable locally and allows for a malicious font in a Java program to cause denial of service, and a low chance of information disclosure or arbitrary code execution.
- CVE-2026-22018 in the Libraries component. Rated as 3.7 Low. Remotely exploitable vulnerability with High attack complexity and no privileges required. It allows for a remote attacker to crash a Java program.
- CVE-2026-22007 in the Security component. Rated as 2.9 Low. Local attackers can possibly access all information on a system that a Java process can access without any privileges required or user interaction.
- CVE-2026-34628 in the Security component. Rated as 2.9 Low. Local attackers can possibly access all information on a system that a Java process can access without any privileges required or user interaction.
Note that of the above vulnerabilities, only the FreeType and the JGSS issues require any user interaction to successfully exploit.
Change History (10)
comment:1 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
comment:3 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:5 by , 6 weeks ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
comment:7 by , 5 weeks ago
| Owner: | changed from to |
|---|
Updated at commit c1a60c3603. Leaving open for SA.
comment:8 by , 5 weeks ago
| Milestone: | 13.1 → 98-Security |
|---|
comment:9 by , 5 weeks ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.0-211 has been issued.
comment:10 by , 5 weeks ago
There are more security fixes in 21.0.12:
- CVE-2026-41254 in the 2D component (little CMS), rated as high (7.5). Low attack complexity and no privileges required. Not affecting us, since we use system littleCMS.
- CVE-2026-47063 in libraries, rated as high (7.5). Low attack complexity and no privileges required.
- CVE-2026-60147 in the security component, rated as medium (6.5). Low attack complexity and no privileges required.
- CVE-2026-46968 in the JSSE component, rated as medium (5.9). High attack complexity and no privileges required
- CVE-2026-47027 in libraries, rated as medium (5.3). Low attack complexity and no privileges required.
- CVE-2026-47021 in the 2D component, rated as medium (5.3). Low attack complexity and no privileges required.
- CVE-2026-46917 in the JSSE component, rated as medium (5.3). Low attack complexity and no privileges required.
- CVE-2026-47059 in the 2D component, rated as medium (5.9). High attack complexity and no privileges required.
- CVE-2026-47010 in the ImageIO component, rated as low (3.7). High attack complexity and no privileges required.
See nvd site for details.
Note:
See TracTickets
for help on using tickets.

I'm going to reassign these to the book for now so whoever wants to do them can do them.
In the meantime I will continue working on rivendell, but I do not want to continue holding the project back on important issues.