RHSA-2026:52949HighCVSS 8.1

Red Hat Security Advisory: java-1.8.0-ibm security update

Published
August 10, 2026
Last Modified
August 13, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2026-8400 — java-1.8.0-ibm: Arbitrary class loading and instantiation via malicious IIOP server CVE-2026-16243 — Eclipse OMR: Eclipse OMR: Denial of service via improper input validation in arraycmp SIMD CVE-2026-16439 — Eclipse Foundation OpenJ9: Eclipse OpenJ9: Buffer underflow via tracing method arguments CVE-2026-16441 — Eclipse Foundation OpenJ9: Eclipse OpenJ9: Incorrect method delegation can lead to integrity issues CVE-2026-41254 — Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize CVE-2026-46968 — openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07) CVE-2026-47010 — openjdk: Enhance JPEG handling (Oracle CPU 2026-07) CVE-2026-47021 — openjdk: Enhance XBM image support (Oracle CPU 2026-07) CVE-2026-47027 — openjdk: Enhance Jar file processing (Oracle CPU 2026-07) CVE-2026-47057 — openjdk: Improve Nashorn index handling (Oracle CPU 2026-07) CVE-2026-47058 — openjdk: Enhance Dataview Implementation (Oracle CPU 2026-07) CVE-2026-47059 — openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07) CVE-2026-47063 — openjdk: Enhance Jar handling (Oracle CPU 2026-07) CVE-2026-60147 — openjdk: Improve certification checking (Oracle CPU 2026-07)

🎯 Affected products23

  • Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10.s390x as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-demo-1:1.8.0.8.70-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-demo-1:1.8.0.8.70-1.el8_10.s390x as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-demo-1:1.8.0.8.70-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-devel-1:1.8.0.8.70-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-devel-1:1.8.0.8.70-1.el8_10.s390x as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-devel-1:1.8.0.8.70-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-headless-1:1.8.0.8.70-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-headless-1:1.8.0.8.70-1.el8_10.s390x as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-headless-1:1.8.0.8.70-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-jdbc-1:1.8.0.8.70-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-jdbc-1:1.8.0.8.70-1.el8_10.s390x as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-jdbc-1:1.8.0.8.70-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-plugin-1:1.8.0.8.70-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-plugin-1:1.8.0.8.70-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-src-1:1.8.0.8.70-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-src-1:1.8.0.8.70-1.el8_10.s390x as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-src-1:1.8.0.8.70-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-webstart-1:1.8.0.8.70-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
  • java-1.8.0-ibm-webstart-1:1.8.0.8.70-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, ensure that applications are configured to only connect to trusted IIOP servers. Restrict network access to prevent connections to untrusted or external IIOP endpoints. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (17)