{"id":"CLSA-2026-1771408532","summary":"java-21-openjdk: Fix of 3 CVEs","details":"- Update to jdk-21.0.10+7\n- CVE-2026-21945: fix possible DOS\n- CVE-2025-65018: fix libpng heap buffer overflow in png_image_finish_read when\n  processing 16-bit interlaced PNGs with 8-bit output format\n- CVE-2025-64720: fix libpng out-of-bounds read in png_image_read_composite when\n  processing palette images with PNG_FLAG_OPTIMIZE_ALPHA enabled","modified":"2026-05-27T11:17:47.520579267Z","published":"2026-02-18T16:49:34Z","upstream":["CVE-2026-21945","CVE-2025-65018","CVE-2025-64720"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/tuxcare9.6esu/CLSA-2026-1771408532.html"}],"affected":[{"package":{"name":"java-21-openjdk","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-demo","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-demo?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-demo-fastdebug","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-demo-fastdebug?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-demo-slowdebug","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-demo-slowdebug?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-devel","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-devel?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-devel-fastdebug","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-devel-fastdebug?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-devel-slowdebug","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-devel-slowdebug?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-fastdebug","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-fastdebug?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-headless","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-headless?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-headless-fastdebug","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-headless-fastdebug?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-headless-slowdebug","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-headless-slowdebug?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-javadoc","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-javadoc?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-javadoc-zip","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-javadoc-zip?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-jmods","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-jmods?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-jmods-fastdebug","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-jmods-fastdebug?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-jmods-slowdebug","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-jmods-slowdebug?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-slowdebug","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-slowdebug?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-src","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-src?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-src-fastdebug","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-src-fastdebug?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-src-slowdebug","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-src-slowdebug?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-static-libs","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-static-libs?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-static-libs-fastdebug","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-static-libs-fastdebug?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}},{"package":{"name":"java-21-openjdk-static-libs-slowdebug","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/java-21-openjdk-static-libs-slowdebug?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:21.0.10.0.7-1.el9.alma.1.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1771408532.json"}}],"schema_version":"1.7.5"}