RHSA-2026:48845HighCVSS 7.5

Red Hat Security Advisory: OpenJDK 25.0.4 Security Update for Windows Builds

Published
July 30, 2026
Last Modified
August 10, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2026-41254 — Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize CVE-2026-46917 — openjdk: Improve DTLS handshaking (Oracle CPU 2026-07) CVE-2026-46968 — openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07) CVE-2026-47010 — openjdk: Enhance JPEG handling (Oracle CPU 2026-07) CVE-2026-47021 — openjdk: Enhance XBM image support (Oracle CPU 2026-07) CVE-2026-47027 — openjdk: Enhance Jar file processing (Oracle CPU 2026-07) CVE-2026-47059 — openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07) CVE-2026-47063 — openjdk: Enhance Jar handling (Oracle CPU 2026-07) CVE-2026-60147 — openjdk: Improve certification checking (Oracle CPU 2026-07)

🎯 Affected products1

  • Temurin Build of OpenJDK 25.0.4

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (13)