Updated java-21-openjdk & java-17-openjdk packages fix security vulnerabilities
Publication date: 12 Sep 2026Modification date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-46968 , CVE-2026-46917 , CVE-2026-47010 , CVE-2026-47021 , CVE-2026-47027 , CVE-2026-60147 , CVE-2026-47059 , CVE-2026-47063 , CVE-2026-60589 , CVE-2026-61308 , CVE-2026-70907
Description
Enhance TLS certificate handling. (CVE-2026-46968)
Improve DTLS handshaking. (CVE-2026-46917)
Enhance JPEG handling. (CVE-2026-47010)
Enhance XBM image support. (CVE-2026-47021)
Enhance Jar file processing. (CVE-2026-47027)
Improve certification checking. (CVE-2026-60147)
Enhance AWT ImagingLib. (CVE-2026-47059)
Enhance Jar handling. (CVE-2026-47063)
Improve Resource Resolving. (CVE-2026-60589)
Enhance HTTP Connections. (CVE-2026-61308)
Enhance TLS server. (CVE-2026-70907)
References
- https://bugs.mageia.org/show_bug.cgi?id=36125
- https://access.redhat.com/errata/RHSA-2026:42889
- https://access.redhat.com/errata/RHSA-2026:55782
- https://access.redhat.com/errata/RHSA-2026:42897
- https://access.redhat.com/errata/RHSA-2026:55788
- https://www.oracle.com/security-alerts/cpujul2026.html#AppendixJAVA
- https://www.oracle.com/security-alerts/cspuaug2026.html#AppendixJAVA
- https://www.cve.org/CVERecord?id=CVE-2026-46968
- https://www.cve.org/CVERecord?id=CVE-2026-46917
- https://www.cve.org/CVERecord?id=CVE-2026-47010
- https://www.cve.org/CVERecord?id=CVE-2026-47021
- https://www.cve.org/CVERecord?id=CVE-2026-47027
- https://www.cve.org/CVERecord?id=CVE-2026-60147
- https://www.cve.org/CVERecord?id=CVE-2026-47059
- https://www.cve.org/CVERecord?id=CVE-2026-47063
- https://www.cve.org/CVERecord?id=CVE-2026-60589
- https://www.cve.org/CVERecord?id=CVE-2026-61308
- https://www.cve.org/CVERecord?id=CVE-2026-70907
SRPMS
10/core
- java-21-openjdk-21.0.12.1.1-1.mga10
9/core
- java-17-openjdk-17.0.20.1.1-1.mga9