Back Linuxsecurity openSUSE Java-17-OpenJDK Important Denial of Service Fix 2026-21440
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
This update for java-17-openjdk fixes the following issues
- Upgrade to upstream tag jdk-17.0.20+8 (July 2026 CPU)
- CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994).
- CVE-2026-46917: partial denial of service via TLS (bsc#1272223).
- CVE-2026-46968: unauthorized creation, deletion or modification access to critical data (bsc#1272224).
- CVE-2026-47010: unauthorized update, insert or delete access (bsc#1272225).
- CVE-2026-47021: partial denial of service via multiple network protocols (bsc#1272227).
- CVE-2026-47027: partial denial of service via multiple network protocols (bsc#1272228).
- CVE-2026-47059: partial denial of service via multiple network protocols (bsc#1272235).
- CVE-2026-47063: unauthorized creation, deletion or modification access to critical data (bsc#1272236).
- CVE-2026-60147: unauthorized update, insert or delete access (bsc#1272237).
To install this openSUSE security update...
- openSUSE Leap 16.0:
java-17-openjdk-17.0.20.0-160000.1.1
java-17-openjdk-demo-17.0.20.0-160000.1.1
java-17-openjdk-devel-17.0.20.0-160000.1.1
java-17-openjdk-headless-17.0.20.0-160000.1.1
java-17-openjdk-javadoc-17.0.20.0-160000.1.1
java-17-openjdk-jmods-17.0.20.0-160000.1.1
java-17-openjdk-src-17.0.20.0-160000.1.1
*
*
*
*
*
*
*
*
*
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
