USN-8783-1

Source
https://ubuntu.com/security/notices/USN-8783-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8783-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-8783-1
Upstream
CVE (4)
Published
2026-09-21T01:42:22Z
Modified
2026-09-22T10:00:29Z
Summary
openjdk-25 vulnerabilities
Details

Weber Leon discovered that the 2D component of OpenJDK 25 did not correctly handle user authentication. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-70906)

Kai Aizen discovered that the Networking component of OpenJDK 25 did not correctly handle user authentication. A remote attacker could possibly use this issue to leak sensitive information. (CVE-2026-61308)

It was discovered that the JSSE component of OpenJDK 25 did not correctly handle user authentication. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-70907)

It was discovered that the Security component of OpenJDK 25 did not correctly handle user authentication. A remote attacker could possibly use this issue to leak sensitive information. (CVE-2026-60589)

References

Affected packages

Ubuntu:22.04:LTS / openjdk-25

Package

Name
openjdk-25
Purl
pkg:deb/ubuntu/openjdk-25?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
25.0.4.1+1-1~22.04.4

Affected versions

25+36-1~22.*
25+36-1~22.04.2
25.*
25.0.1+8-1~22.04
25.0.2+10-1~22.04
25.0.3+9-2~22.04.2
25.0.4+7-1~22.04

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "openjdk-25-demo",
            "binary_version":  "25.0.4.1+1-1~22.04.4"
        },
        {
            "binary_name":  "openjdk-25-jdk",
            "binary_version":  "25.0.4.1+1-1~22.04.4"
        },
        {
            "binary_name":  "openjdk-25-jdk-headless",
            "binary_version":  "25.0.4.1+1-1~22.04.4"
        },
        {
            "binary_name":  "openjdk-25-jre",
            "binary_version":  "25.0.4.1+1-1~22.04.4"
        },
        {
            "binary_name":  "openjdk-25-jre-headless",
            "binary_version":  "25.0.4.1+1-1~22.04.4"
        },
        {
            "binary_name":  "openjdk-25-jre-zero",
            "binary_version":  "25.0.4.1+1-1~22.04.4"
        },
        {
            "binary_name":  "openjdk-25-source",
            "binary_version":  "25.0.4.1+1-1~22.04.4"
        },
        {
            "binary_name":  "openjdk-25-testsupport",
            "binary_version":  "25.0.4.1+1-1~22.04.4"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2026-60589",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-61308",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-70906",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-70907",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:22.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8783-1.json"

Ubuntu:24.04:LTS / openjdk-25

Package

Name
openjdk-25
Purl
pkg:deb/ubuntu/openjdk-25?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
25.0.4.1+1-1~24.04.4

Affected versions

25+36-1~24.*
25+36-1~24.04.2
25.*
25.0.1+8-1~24.04
25.0.2+10-1~24.04
25.0.3+9-2~24.04.2
25.0.4+7-1~24.04

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "openjdk-25-demo",
            "binary_version":  "25.0.4.1+1-1~24.04.4"
        },
        {
            "binary_name":  "openjdk-25-jdk",
            "binary_version":  "25.0.4.1+1-1~24.04.4"
        },
        {
            "binary_name":  "openjdk-25-jdk-headless",
            "binary_version":  "25.0.4.1+1-1~24.04.4"
        },
        {
            "binary_name":  "openjdk-25-jre",
            "binary_version":  "25.0.4.1+1-1~24.04.4"
        },
        {
            "binary_name":  "openjdk-25-jre-headless",
            "binary_version":  "25.0.4.1+1-1~24.04.4"
        },
        {
            "binary_name":  "openjdk-25-jre-zero",
            "binary_version":  "25.0.4.1+1-1~24.04.4"
        },
        {
            "binary_name":  "openjdk-25-source",
            "binary_version":  "25.0.4.1+1-1~24.04.4"
        },
        {
            "binary_name":  "openjdk-25-testsupport",
            "binary_version":  "25.0.4.1+1-1~24.04.4"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2026-60589",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-61308",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-70906",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-70907",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:24.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8783-1.json"

Ubuntu:26.04:LTS / openjdk-25

Package

Name
openjdk-25
Purl
pkg:deb/ubuntu/openjdk-25?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
25.0.4.1+1-1~26.04.4

Affected versions

Other
25+36-1
25.*
25.0.1+8-1
25.0.1+8-2
25.0.1+8-3
25.0.2+10-1
25.0.3~5ea-2
25.0.3~7ea-2
25.0.3+9-2~26.04.2
25.0.4+7-1~26.04

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "openjdk-25-demo",
            "binary_version":  "25.0.4.1+1-1~26.04.4"
        },
        {
            "binary_name":  "openjdk-25-jdk",
            "binary_version":  "25.0.4.1+1-1~26.04.4"
        },
        {
            "binary_name":  "openjdk-25-jdk-headless",
            "binary_version":  "25.0.4.1+1-1~26.04.4"
        },
        {
            "binary_name":  "openjdk-25-jre",
            "binary_version":  "25.0.4.1+1-1~26.04.4"
        },
        {
            "binary_name":  "openjdk-25-jre-headless",
            "binary_version":  "25.0.4.1+1-1~26.04.4"
        },
        {
            "binary_name":  "openjdk-25-jre-zero",
            "binary_version":  "25.0.4.1+1-1~26.04.4"
        },
        {
            "binary_name":  "openjdk-25-source",
            "binary_version":  "25.0.4.1+1-1~26.04.4"
        },
        {
            "binary_name":  "openjdk-25-testsupport",
            "binary_version":  "25.0.4.1+1-1~26.04.4"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [
        {
            "id":  "CVE-2026-60589",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-61308",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-70906",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        },
        {
            "id":  "CVE-2026-70907",
            "severity":  [
                {
                    "score":  "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                    "type":  "CVSS_V3"
                },
                {
                    "score":  "medium",
                    "type":  "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem":  "Ubuntu:26.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8783-1.json"