openSUSE-SU-2026:21759-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21759-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21759-1
Upstream
CVE (3)
  • CVE-2026-60589
  • CVE-2026-61308
  • CVE-2026-70907
Related
Published
2026-09-04T09:08:15Z
Modified
2026-09-09T18:23:14Z
Summary
Security update for java-21-openjdk
Details

This update for java-21-openjdk fixes the following issues:

Security issues fixed:

  • CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777).
  • CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778).
  • CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764).

Non security issue fixed:

  • java-21-openjdk classlist depends on the CPU count of the build machine (bsc#1221224).

Changes for java-21-openjdk:

  • Update to jdk-21.0.12.1+1 (August 2026 CSPU)
  • backport upcoming upgrade of timezone data (bsc#1275035)
  • Explicitly use G1 if the JVM supports it. GC ergonomics pick SerialGC on single-CPU machines. SerialGC does not support dumping of the shared heap, thus the classlist is different on a single-CPU builder.
References

Affected packages

openSUSE:Leap 16.0 / java-21-openjdk

Package

Name
java-21-openjdk
Purl
pkg:rpm/opensuse/java-21-openjdk&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
21.0.12.1-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "java-21-openjdk":  "21.0.12.1-160000.1.1",
            "java-21-openjdk-demo":  "21.0.12.1-160000.1.1",
            "java-21-openjdk-devel":  "21.0.12.1-160000.1.1",
            "java-21-openjdk-headless":  "21.0.12.1-160000.1.1",
            "java-21-openjdk-javadoc":  "21.0.12.1-160000.1.1",
            "java-21-openjdk-jmods":  "21.0.12.1-160000.1.1",
            "java-21-openjdk-src":  "21.0.12.1-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21759-1.json"