{"id":"MGASA-2025-0268","summary":"Updated java-1.8.0-openjdk, java-11-openjdk, java-17-openjdk & java-latest-openjdk packages fix security vulnerabilities","details":"Difficult to exploit vulnerability allows unauthenticated attacker with\nnetwork access via multiple protocols to compromise Oracle Java SE,\nOracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful\nattacks of this vulnerability can result in unauthorized creation,\ndeletion or modification access to critical data or all Oracle Java SE,\nOracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible\ndata. Note: This vulnerability can be exploited by using APIs in the\nspecified Component, e.g., through a web service which supplies data to\nthe APIs. This vulnerability also applies to Java deployments, typically\nin clients running sandboxed Java Web Start applications or sandboxed\nJava applets, that load and run untrusted code (e.g., code that comes\nfrom the internet) and rely on the Java sandbox for security.\n(CVE-2025-53057)\nEasily exploitable vulnerability allows unauthenticated attacker with\nnetwork access via multiple protocols to compromise Oracle Java SE,\nOracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful\nattacks of this vulnerability can result in unauthorized access to\ncritical data or complete access to all Oracle Java SE, Oracle GraalVM\nfor JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This\nvulnerability can be exploited by using APIs in the specified Component,\ne.g., through a web service which supplies data to the APIs. This\nvulnerability also applies to Java deployments, typically in clients\nrunning sandboxed Java Web Start applications or sandboxed Java applets,\nthat load and run untrusted code (e.g., code that comes from the\ninternet) and rely on the Java sandbox for security. (CVE-2025-53066)\n","modified":"2026-04-16T00:11:01.426851540Z","published":"2025-11-07T01:54:56Z","upstream":["CVE-2025-53057","CVE-2025-53066"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2025-0268.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=34697"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:18815"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:18818"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:18821"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2025.html#AppendixJAVA"}],"affected":[{"package":{"name":"java-1.8.0-openjdk","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/java-1.8.0-openjdk?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0.472.b08-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2025-0268.json"}},{"package":{"name":"java-11-openjdk","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/java-11-openjdk?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.0.29.0.7-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2025-0268.json"}},{"package":{"name":"java-17-openjdk","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/java-17-openjdk?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.0.17.0.10-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2025-0268.json"}},{"package":{"name":"java-latest-openjdk","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/java-latest-openjdk?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"25.0.1.0.8-1.rolling.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2025-0268.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}