ALSA-2026:45115: kernel security update (Important)
ALSA-2026:45116: kernel-rt security update (Important)
ALSA-2026:42877: java-1.8.0-openjdk security update (Important)
ALSA-2026:42895: java-21-openjdk security update (Important)
ALSA-2026:42887: java-17-openjdk security update (Important)
ALSA-2026:42877: java-1.8.0-openjdk security update (Important)
ALSA-2026:43307: kernel security, bug fix, and enhancement update (Important)
ALSA-2026:42887: java-17-openjdk security update (Important)
ALSA-2026:42122: sssd security update (Important)
ALSA-2026:42895: java-21-openjdk security update (Important)
ALSA-2026:44438: compat-openssl11 security update (Important)
ALSA-2026:42919: kernel security, bug fix, and enhancement update (Important)
ALSA-2026:42895: java-21-openjdk security update (Important)
ALSA-2026:45115: kernel security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-07-24
Summary:
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
* kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (CVE-2025-40026)
* kernel: xfrm single-frag length not properly limited
* kernel: dm log: fix out-of-bounds write due to region_count overflow (CVE-2026-53059)
* kernel: tipc: fix double-free in tipc_buf_append() (CVE-2026-52993)
Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-45115.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:45116: kernel-rt security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-07-24
Summary:
The kernel-rt packages provide the Real Time Linux Kernel, which enables
fine-tuning for systems with extremely high determinism requirements.
Security Fix(es):
* kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (CVE-2025-40026)
* kernel: xfrm single-frag length not properly limited
* kernel: dm log: fix out-of-bounds write due to region_count overflow (CVE-2026-53059)
* kernel: tipc: fix double-free in tipc_buf_append() (CVE-2026-52993)
Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-45116.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:42877: java-1.8.0-openjdk security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-07-24
Summary:
The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.
Security Fix(es):
* JDK: Enhance TLS certificate handling (CVE-2026-46968)
* JDK: Enhance JPEG handling (CVE-2026-47010)
* JDK: Enhance XBM image support (CVE-2026-47021)
* JDK: Enhance Jar file processing (CVE-2026-47027)
* JDK: Improve certification checking (CVE-2026-60147)
* JDK: Enhance AWT ImagingLib (CVE-2026-47059)
* JDK: Enhance Jar handling (CVE-2026-47063)
* JDK: Improve Nashorn index handling (CVE-2026-47057)
* JDK: Enhance Dataview Implementation (CVE-2026-47058)
* JDK: Update LCMS to 2.19 (CVE-2026-41254)
Enhancement(s):
* For the last couple of years, OpenJDK has used a single build shared among multiple RPMs and a tarball available on the customer portal. The single "portable" build has a release number ('p') and each RPM has its own release number ('r'). However, the RPM naming only showed the RPM release number, while the version output from the build showed the portable release number, making it unclear that they were different numbers. From this release onwards, a release field of the form 'p.r' is always used for RPMs and the version output shows 'p'. (AlmaLinux-212308, AlmaLinux-212309, AlmaLinux-212310, AlmaLinux-212311, AlmaLinux-212312, AlmaLinux-212313, AlmaLinux-212314, AlmaLinux-212315)
Bug Fix(es):
* In previous releases, the RPM did not correctly own the subdirectories used for documentation in /usr/share/doc and /usr/share/javadoc. This is fixed in this release, so these subdirectories will be removed when the package is uninstalled. (AlmaLinux-212319, AlmaLinux-212320, AlmaLinux-212321, AlmaLinux-212322, AlmaLinux-212323, AlmaLinux-212324, AlmaLinux-212325, AlmaLinux-212326)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-42877.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:42895: java-21-openjdk security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-07-24
Summary:
The OpenJDK 21 packages provide the OpenJDK 21 Java Runtime Environment and the OpenJDK 21 Java Software Development Kit.
Security Fix(es):
* JDK: Enhance TLS certificate handling (CVE-2026-46968)
* JDK: Improve DTLS handshaking (CVE-2026-46917)
* JDK: Enhance JPEG handling (CVE-2026-47010)
* JDK: Enhance XBM image support (CVE-2026-47021)
* JDK: Enhance Jar file processing (CVE-2026-47027)
* JDK: Improve certification checking (CVE-2026-60147)
* JDK: Enhance AWT ImagingLib (CVE-2026-47059)
* JDK: Enhance Jar handling (CVE-2026-47063)
* JDK: Update LCMS to 2.19 (CVE-2026-41254)
Enhancement(s):
* For the last couple of years, OpenJDK has used a single build shared among multiple RPMs and a tarball available on the customer portal. The single "portable" build has a release number ('p') and each RPM has its own release number ('r'). However, the RPM naming only showed the RPM release number, while the version output from the build showed the portable release number, making it unclear that they were different numbers. From this release onwards, a release field of the form 'p.r' is always used for RPMs and the version output shows 'p'. (AlmaLinux-212337, AlmaLinux-212338, AlmaLinux-212339, AlmaLinux-212340, AlmaLinux-212342, AlmaLinux-212343)
Bug Fix(es):
* In previous releases, the RPM did not correctly own the subdirectories used for documentation in /usr/share/doc and /usr/share/javadoc. This is fixed in this release, so these subdirectories will be removed when the package is uninstalled. (AlmaLinux-212353, AlmaLinux-212359, AlmaLinux-212360, AlmaLinux-212361)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-42895.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:42887: java-17-openjdk security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-07-24
Summary:
The java-17-openjdk packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit.
Security Fix(es):
* JDK: Enhance TLS certificate handling (CVE-2026-46968)
* JDK: Improve DTLS handshaking (CVE-2026-46917)
* JDK: Enhance JPEG handling (CVE-2026-47010)
* JDK: Enhance XBM image support (CVE-2026-47021)
* JDK: Enhance Jar file processing (CVE-2026-47027)
* JDK: Improve certification checking (CVE-2026-60147)
* JDK: Enhance AWT ImagingLib (CVE-2026-47059)
* JDK: Enhance Jar handling (CVE-2026-47063)
* JDK: Update LCMS to 2.19 (CVE-2026-41254)
Enhancement(s):
* For the last couple of years, OpenJDK has used a single build shared among multiple RPMs and a tarball available on the customer portal. The single "portable" build has a release number ('p') and each RPM has its own release number ('r'). However, the RPM naming only showed the RPM release number, while the version output from the build showed the portable release number, making it unclear that they were different numbers. From this release onwards, a release field of the form 'p.r' is always used for RPMs and the version output shows 'p'. (AlmaLinux-212474, AlmaLinux-212475, AlmaLinux-212476, AlmaLinux-212477, AlmaLinux-212478, AlmaLinux-212479, AlmaLinux-212480, AlmaLinux-212481)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-42887.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:42877: java-1.8.0-openjdk security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-07-24
Summary:
The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.
Security Fix(es):
* JDK: Enhance TLS certificate handling (CVE-2026-46968)
* JDK: Enhance JPEG handling (CVE-2026-47010)
* JDK: Enhance XBM image support (CVE-2026-47021)
* JDK: Enhance Jar file processing (CVE-2026-47027)
* JDK: Improve certification checking (CVE-2026-60147)
* JDK: Enhance AWT ImagingLib (CVE-2026-47059)
* JDK: Enhance Jar handling (CVE-2026-47063)
* JDK: Improve Nashorn index handling (CVE-2026-47057)
* JDK: Enhance Dataview Implementation (CVE-2026-47058)
* JDK: Update LCMS to 2.19 (CVE-2026-41254)
Enhancement(s):
* For the last couple of years, OpenJDK has used a single build shared among multiple RPMs and a tarball available on the customer portal. The single "portable" build has a release number ('p') and each RPM has its own release number ('r'). However, the RPM naming only showed the RPM release number, while the version output from the build showed the portable release number, making it unclear that they were different numbers. From this release onwards, a release field of the form 'p.r' is always used for RPMs and the version output shows 'p'. (AlmaLinux-212308, AlmaLinux-212309, AlmaLinux-212310, AlmaLinux-212311, AlmaLinux-212312, AlmaLinux-212313, AlmaLinux-212314, AlmaLinux-212315)
Bug Fix(es):
* In previous releases, the RPM did not correctly own the subdirectories used for documentation in /usr/share/doc and /usr/share/javadoc. This is fixed in this release, so these subdirectories will be removed when the package is uninstalled. (AlmaLinux-212319, AlmaLinux-212320, AlmaLinux-212321, AlmaLinux-212322, AlmaLinux-212323, AlmaLinux-212324, AlmaLinux-212325, AlmaLinux-212326)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-42877.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:43307: kernel security, bug fix, and enhancement update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-07-24
Summary:
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
* kernel: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CVE-2025-71113)
* kernel: scsi: core: Wake up the error handler when final completions race against each other (CVE-2026-23110)
* kernel: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (CVE-2026-46099)
* kernel: fanotify: fix false positive on permission events (CVE-2026-46150)
* kernel: drm: Set old handle to NULL before prime swap in change_handle (CVE-2026-46215)
* kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071)
Bug Fix(es) and Enhancement(s):
* [AlmaLinux9] tools/lib/perf/Makefile: libperf includes appended after CFLAGS causes parallel build race, breaking kernel builds [almalinux-9.8.z] (JIRA:AlmaLinux-183980)
* [AlmaLinux-9.8.z]: mlx5: include bug fixes (JIRA:AlmaLinux-188121)
* dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() [almalinux-9.8.z] (JIRA:AlmaLinux-212061)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-43307.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:42887: java-17-openjdk security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-07-24
Summary:
The java-17-openjdk packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit.
Security Fix(es):
* JDK: Enhance TLS certificate handling (CVE-2026-46968)
* JDK: Improve DTLS handshaking (CVE-2026-46917)
* JDK: Enhance JPEG handling (CVE-2026-47010)
* JDK: Enhance XBM image support (CVE-2026-47021)
* JDK: Enhance Jar file processing (CVE-2026-47027)
* JDK: Improve certification checking (CVE-2026-60147)
* JDK: Enhance AWT ImagingLib (CVE-2026-47059)
* JDK: Enhance Jar handling (CVE-2026-47063)
* JDK: Update LCMS to 2.19 (CVE-2026-41254)
Enhancement(s):
* For the last couple of years, OpenJDK has used a single build shared among multiple RPMs and a tarball available on the customer portal. The single "portable" build has a release number ('p') and each RPM has its own release number ('r'). However, the RPM naming only showed the RPM release number, while the version output from the build showed the portable release number, making it unclear that they were different numbers. From this release onwards, a release field of the form 'p.r' is always used for RPMs and the version output shows 'p'. (AlmaLinux-212474, AlmaLinux-212475, AlmaLinux-212476, AlmaLinux-212477, AlmaLinux-212478, AlmaLinux-212479, AlmaLinux-212480, AlmaLinux-212481)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-42887.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:42122: sssd security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-07-24
Summary:
The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to multiple different account sources.
Security Fix(es):
* sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (CVE-2026-14474)
* sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (CVE-2026-14476)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-42122.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:42895: java-21-openjdk security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-07-24
Summary:
The OpenJDK 21 packages provide the OpenJDK 21 Java Runtime Environment and the OpenJDK 21 Java Software Development Kit.
Security Fix(es):
* JDK: Enhance TLS certificate handling (CVE-2026-46968)
* JDK: Improve DTLS handshaking (CVE-2026-46917)
* JDK: Enhance JPEG handling (CVE-2026-47010)
* JDK: Enhance XBM image support (CVE-2026-47021)
* JDK: Enhance Jar file processing (CVE-2026-47027)
* JDK: Improve certification checking (CVE-2026-60147)
* JDK: Enhance AWT ImagingLib (CVE-2026-47059)
* JDK: Enhance Jar handling (CVE-2026-47063)
* JDK: Update LCMS to 2.19 (CVE-2026-41254)
Enhancement(s):
* For the last couple of years, OpenJDK has used a single build shared among multiple RPMs and a tarball available on the customer portal. The single "portable" build has a release number ('p') and each RPM has its own release number ('r'). However, the RPM naming only showed the RPM release number, while the version output from the build showed the portable release number, making it unclear that they were different numbers. From this release onwards, a release field of the form 'p.r' is always used for RPMs and the version output shows 'p'. (AlmaLinux-212337, AlmaLinux-212338, AlmaLinux-212339, AlmaLinux-212340, AlmaLinux-212342, AlmaLinux-212343)
Bug Fix(es):
* In previous releases, the RPM did not correctly own the subdirectories used for documentation in /usr/share/doc and /usr/share/javadoc. This is fixed in this release, so these subdirectories will be removed when the package is uninstalled. (AlmaLinux-212353, AlmaLinux-212359, AlmaLinux-212360, AlmaLinux-212361)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-42895.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:44438: compat-openssl11 security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-07-24
Summary:
The OpenSSL toolkit provides support for secure communications between machines. This version of OpenSSL package contains only the libraries from the 1.1.1 version and is provided for compatibility with previous releases.
Security Fix(es):
* openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() (CVE-2026-45447)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-44438.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:42919: kernel security, bug fix, and enhancement update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-07-24
Summary:
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
* kernel: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CVE-2025-71113)
* kernel: Linux kernel: Denial of Service due to memory leak in tpm2_load_cmd (CVE-2025-71147)
* kernel: flex_proportions: make fprop_new_period() hardirq safe (CVE-2026-23168)
* kernel: cxl/port: Fix use after free of parent_port in cxl_detach_ep() (CVE-2026-31530)
* kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)
* kernel: fanotify: fix false positive on permission events (CVE-2026-46150)
* kernel: drm: Set old handle to NULL before prime swap in change_handle (CVE-2026-46215)
* kernel: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (CVE-2026-52976)
* kernel: drm/xe/dma-buf: fix UAF with retry loop (CVE-2026-52950)
* kernel: ice: fix double-free of tx_buf skb (CVE-2026-53009)
* kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071)
* kernel: can: bcm: thrtimer use-after-free during RX operation teardown ()
Bug Fix(es) and Enhancement(s):
* nfsd_file slab cache objects remaining on kmem_cache_shutdown during nfsd teardown while running bz1477872 testcase (JIRA:AlmaLinux-173103)
* tools/lib/perf/Makefile: libperf includes appended after CFLAGS causes parallel build race, breaking kernel builds [almalinux-10.2.z] (JIRA:AlmaLinux-183975)
* [AlmaLinux10-debug]: BUG: KASAN: slab-use-after-free in __pv_queued_spin_lock_slowpath [almalinux-10.2.z] (JIRA:AlmaLinux-186311)
* ice: driver update 2026-06, part 1 [almalinux-10.2.z] (JIRA:AlmaLinux-191324)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-42919.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team
ALSA-2026:42895: java-21-openjdk security update (Important)
Hi,
You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.
AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-07-24
Summary:
The OpenJDK 21 packages provide the OpenJDK 21 Java Runtime Environment and the OpenJDK 21 Java Software Development Kit.
Security Fix(es):
* JDK: Enhance TLS certificate handling (CVE-2026-46968)
* JDK: Improve DTLS handshaking (CVE-2026-46917)
* JDK: Enhance JPEG handling (CVE-2026-47010)
* JDK: Enhance XBM image support (CVE-2026-47021)
* JDK: Enhance Jar file processing (CVE-2026-47027)
* JDK: Improve certification checking (CVE-2026-60147)
* JDK: Enhance AWT ImagingLib (CVE-2026-47059)
* JDK: Enhance Jar handling (CVE-2026-47063)
* JDK: Update LCMS to 2.19 (CVE-2026-41254)
Enhancement(s):
* For the last couple of years, OpenJDK has used a single build shared among multiple RPMs and a tarball available on the customer portal. The single "portable" build has a release number ('p') and each RPM has its own release number ('r'). However, the RPM naming only showed the RPM release number, while the version output from the build showed the portable release number, making it unclear that they were different numbers. From this release onwards, a release field of the form 'p.r' is always used for RPMs and the version output shows 'p'. (AlmaLinux-212337, AlmaLinux-212338, AlmaLinux-212339, AlmaLinux-212340, AlmaLinux-212342, AlmaLinux-212343)
Bug Fix(es):
* In previous releases, the RPM did not correctly own the subdirectories used for documentation in /usr/share/doc and /usr/share/javadoc. This is fixed in this release, so these subdirectories will be removed when the package is uninstalled. (AlmaLinux-212353, AlmaLinux-212359, AlmaLinux-212360, AlmaLinux-212361)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-42895.html
This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.
Kind regards,
AlmaLinux Team