{"id":"SUSE-SU-2026:22944-1","summary":"Security update for java-17-openjdk","details":"This update for java-17-openjdk fixes the following issues\n\n- Upgrade to upstream tag jdk-17.0.20+8 (July 2026 CPU)\n- CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994).\n- CVE-2026-46917: partial denial of service via TLS (bsc#1272223).\n- CVE-2026-46968: unauthorized creation, deletion or modification access to critical data (bsc#1272224).\n- CVE-2026-47010: unauthorized update, insert or delete access (bsc#1272225).\n- CVE-2026-47021: partial denial of service via multiple network protocols (bsc#1272227).\n- CVE-2026-47027: partial denial of service via multiple network protocols (bsc#1272228).\n- CVE-2026-47059: partial denial of service via multiple network protocols (bsc#1272235).\n- CVE-2026-47063: unauthorized creation, deletion or modification access to critical data (bsc#1272236).\n- CVE-2026-60147: unauthorized update, insert or delete access (bsc#1272237).\n","modified":"2026-07-29T18:24:17.419679236Z","published":"2026-07-24T08:27:03Z","related":["CVE-2026-41254","CVE-2026-46917","CVE-2026-46968","CVE-2026-47010","CVE-2026-47021","CVE-2026-47027","CVE-2026-47059","CVE-2026-47063","CVE-2026-60147"],"upstream":["CVE-2026-41254","CVE-2026-46917","CVE-2026-46968","CVE-2026-47010","CVE-2026-47021","CVE-2026-47027","CVE-2026-47059","CVE-2026-47063","CVE-2026-60147"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202622944-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264994"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272223"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272224"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272225"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272227"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272228"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272235"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272236"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272237"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41254"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46917"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46968"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47010"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47021"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47027"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47059"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47063"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-60147"}],"affected":[{"package":{"name":"java-17-openjdk","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/java-17-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.0.20.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"java-17-openjdk-devel":"17.0.20.0-160000.1.1","java-17-openjdk-headless":"17.0.20.0-160000.1.1","java-17-openjdk-javadoc":"17.0.20.0-160000.1.1","java-17-openjdk-jmods":"17.0.20.0-160000.1.1","java-17-openjdk-src":"17.0.20.0-160000.1.1","java-17-openjdk":"17.0.20.0-160000.1.1","java-17-openjdk-demo":"17.0.20.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22944-1.json"}},{"package":{"name":"java-17-openjdk","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/java-17-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.0.20.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"java-17-openjdk-src":"17.0.20.0-160000.1.1","java-17-openjdk":"17.0.20.0-160000.1.1","java-17-openjdk-demo":"17.0.20.0-160000.1.1","java-17-openjdk-devel":"17.0.20.0-160000.1.1","java-17-openjdk-headless":"17.0.20.0-160000.1.1","java-17-openjdk-javadoc":"17.0.20.0-160000.1.1","java-17-openjdk-jmods":"17.0.20.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22944-1.json"}}],"schema_version":"1.7.5"}