{
  "schema_version": "1.7.0",
  "id": "MGASA-2026-0395",
  "published": "2026-09-12T03:59:30Z",
  "modified": "2026-09-12T02:30:23Z",
  "summary": "Updated java-21-openjdk & java-17-openjdk packages fix security vulnerabilities",
  "details": "Enhance TLS certificate handling. (CVE-2026-46968)\nImprove DTLS handshaking. (CVE-2026-46917)\nEnhance JPEG handling. (CVE-2026-47010)\nEnhance XBM image support. (CVE-2026-47021)\nEnhance Jar file processing. (CVE-2026-47027)\nImprove certification checking. (CVE-2026-60147)\nEnhance AWT ImagingLib. (CVE-2026-47059)\nEnhance Jar handling. (CVE-2026-47063)\nImprove Resource Resolving. (CVE-2026-60589)\nEnhance HTTP Connections. (CVE-2026-61308)\nEnhance TLS server. (CVE-2026-70907)\n",
  "upstream": [
    "CVE-2026-46968",
    "CVE-2026-46917",
    "CVE-2026-47010",
    "CVE-2026-47021",
    "CVE-2026-47027",
    "CVE-2026-60147",
    "CVE-2026-47059",
    "CVE-2026-47063",
    "CVE-2026-60589",
    "CVE-2026-61308",
    "CVE-2026-70907"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2026-0395.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=36125"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:42889"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:55782"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:42897"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:55788"
    },
    {
      "type": "WEB",
      "url": "https://www.oracle.com/security-alerts/cpujul2026.html#AppendixJAVA"
    },
    {
      "type": "WEB",
      "url": "https://www.oracle.com/security-alerts/cspuaug2026.html#AppendixJAVA"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "java-21-openjdk",
        "purl": "pkg:rpm/mageia/java-21-openjdk?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "21.0.12.1.1-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "java-17-openjdk",
        "purl": "pkg:rpm/mageia/java-17-openjdk?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "17.0.20.1.1-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
