openSUSE-SU-2026:20943-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20943-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20943-1
Upstream
  • CVE-2026-22007
  • CVE-2026-22013
  • CVE-2026-22016
  • CVE-2026-22018
  • CVE-2026-22021
  • CVE-2026-34268
  • CVE-2026-34282
Related
Published
2026-06-11T07:34:54Z
Modified
2026-06-13T18:24:19.600416001Z
Summary
Security update for java-17-openj9
Details

This update for java-17-openj9 fixes the following issues:

Changes in java-17-openj9:

  • Make post scripts less noisy (bsc#1267355)

  • Use libalternatives instead of update-alternatives for distributions where libalternatives is available

  • Update to OpenJDK 17.0.19 with OpenJ9 0.59.0 virtual machine

  • Including Oracle April 2026 CPU changes
    • CVE-2026-22007 (bsc#1262490), CVE-2026-22013 (bsc#1262494), CVE-2026-22016 (bsc#1262495), CVE-2026-22018 (bsc#1262496), CVE-2026-22021 (bsc#1262497), CVE-2026-23865 (bsc#1259118), CVE-2026-34268 (bsc#1262500), CVE-2026-34282 (bsc#1262501)
  • OpenJ9 specific security fix

    • CVE-2026-1188 (bsc#1265261)
    • OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.59/
  • Update to OpenJDK 17.0.18 with OpenJ9 0.57.0 virtual machine

  • Including Oracle January 2026 CPU changes

    • CVE-2026-21925 (bsc#1257034), CVE-2026-21932 (bsc#1257036), CVE-2026-21933 (bsc#1257037), CVE-2026-21945 (bsc#1257038)
    • OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.57/
  • Do not depend on update-desktop-files (jsc#PED-14507)

  • Update to OpenJDK 17.0.17 with OpenJ9 0.56.0 virtual machine

  • Including Oracle October 2025 CPU changes

    • CVE-2025-53057 (bsc#1252414), CVE-2025-53066 (bsc#1252417)
    • OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.56/
  • Update to OpenJDK 17.0.16 with OpenJ9 0.53.0 virtual machine

  • Including Oracle July 2025 CPU changes
    • CVE-2025-30749 (bsc#1246595), CVE-2025-30754 (bsc#1246598), CVE-2025-50059 (bsc#1246575), CVE-2025-50106 (bsc#1246584)
    • OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.53/
  • Enable bootcycle build

  • Do not embed rebuild counter (bsc#1246806)

  • Add -std=gnu99 to CFLAGS to fix gcc15 compile time error. Since the C++ part is on -std=gnu++98, this is the closest.

  • Added patch:

    • fix-build-with-gcc15.patch
      • fix a typo in omr that is fatal with gcc15
  • Update to OpenJDK 17.0.15 with OpenJ9 0.51.0 virtual machine

  • Including Oracle April 2025 CPU changes

    • CVE-2025-21587 (bsc#1241274), CVE-2025-30691 (bsc#1241275), CVE-2025-30698 (bsc#1241276)
    • OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.51/
  • fix wrong execstack flag in libj9jit (bsc#1235844)

  • Update to OpenJDK 17.0.14 with OpenJ9 0.49.0 virtual machine

  • Including Oracle October 2024 and January 2025 CPU changes
    • CVE-2024-21208 (bsc#1231702), CVE-2024-21210 (bsc#1231711), CVE-2024-21217 (bsc#1231716), CVE-2024-21235 (bsc#1231719), CVE-2025-21502 (bsc#1236278)
    • OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.49/
References

Affected packages

openSUSE:Leap 16.0 / java-17-openj9

Package

Name
java-17-openj9
Purl
pkg:rpm/opensuse/java-17-openj9&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
17.0.19.0-bp160.1.1

Ecosystem specific

{
    "binaries": [
        {
            "java-17-openj9-src": "17.0.19.0-bp160.1.1",
            "java-17-openj9": "17.0.19.0-bp160.1.1",
            "java-17-openj9-jmods": "17.0.19.0-bp160.1.1",
            "java-17-openj9-demo": "17.0.19.0-bp160.1.1",
            "java-17-openj9-devel": "17.0.19.0-bp160.1.1",
            "java-17-openj9-headless": "17.0.19.0-bp160.1.1",
            "java-17-openj9-javadoc": "17.0.19.0-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20943-1.json"