SUSE-SU-2026:2036-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262036-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2036-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:2036-1
Upstream
  • CVE-2026-22007
  • CVE-2026-22013
  • CVE-2026-22016
  • CVE-2026-22018
  • CVE-2026-22021
  • CVE-2026-34268
Related
Published
2026-05-21T11:56:21Z
Modified
2026-05-22T09:00:05.164447844Z
Summary
Security update for java-1_8_0-openj9
Details

This update for java-180-openj9 fixes the following issues

  • CVE-2026-1188: eclipse: ensure room for separator in omrsysinfogetprocessorfeaturestring (bsc#1265261).
  • CVE-2026-22007: APIs in the specified component can lead to an unauthorized read access (bsc#1262490).
  • CVE-2026-22013: unauthenticated attacker with network access can access to critical data (bsc#1262494).
  • CVE-2026-22016: APIs in the specified Component can cause unauthorized access to critical data (bsc#1262495).
  • CVE-2026-22018: unauthenticated attacker with network access can cause a partial denial of service (bsc#1262496).
  • CVE-2026-22021: APIs in the specified Component can cause a partial denial of service (bsc#1262497).
  • CVE-2026-23865: Integer overflow in the ttvarloaditemvariation_store function (bsc#1259118).
  • CVE-2026-34268: unauthenticated attacker with logon can gain unauthorized read access (bsc#1262500).

Changes for java-180-openj9:

  • Update to OpenJDK 8u492 build 09 with OpenJ9 0.59.0 virtual machine
References

Affected packages