SUSE-SU-2026:3406-1: important: Security update for java-17-openjdk

SLE-UPDATES null at suse.de
Wed Jul 29 16:33:31 UTC 2026


# Security update for java-17-openjdk

Announcement ID: SUSE-SU-2026:3406-1  
Release Date: 2026-07-29T11:10:17Z  
Rating: important  
References:

  * bsc#1264396
  * bsc#1264994
  * bsc#1267355
  * bsc#1272223
  * bsc#1272224
  * bsc#1272225
  * bsc#1272227
  * bsc#1272228
  * bsc#1272235
  * bsc#1272236
  * bsc#1272237

  
Cross-References:

  * CVE-2026-41254
  * CVE-2026-46917
  * CVE-2026-46968
  * CVE-2026-47010
  * CVE-2026-47021
  * CVE-2026-47027
  * CVE-2026-47059
  * CVE-2026-47063
  * CVE-2026-60147

  
CVSS scores:

  * CVE-2026-41254 ( SUSE ):  2.1
    CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-41254 ( SUSE ):  2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-41254 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-41254 ( NVD ):  4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
  * CVE-2026-46917 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-46917 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-46917 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-46968 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-46968 ( SUSE ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-46968 ( NVD ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-47010 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-47010 ( SUSE ):  3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-47010 ( NVD ):  3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-47021 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-47021 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-47021 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-47027 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-47027 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-47027 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-47059 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-47059 ( SUSE ):  3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-47059 ( NVD ):  3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-47063 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-47063 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-47063 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-60147 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-60147 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-60147 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

  
Affected Products:

  * Legacy Module 15-SP7
  * openSUSE Leap 15.4
  * SUSE Linux Enterprise High Performance Computing 15 SP4
  * SUSE Linux Enterprise High Performance Computing 15 SP5
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
  * SUSE Linux Enterprise Server 15 SP4
  * SUSE Linux Enterprise Server 15 SP4 LTSS
  * SUSE Linux Enterprise Server 15 SP5
  * SUSE Linux Enterprise Server 15 SP5 LTSS
  * SUSE Linux Enterprise Server 15 SP6
  * SUSE Linux Enterprise Server 15 SP6 LTSS
  * SUSE Linux Enterprise Server 15 SP7
  * SUSE Linux Enterprise Server for SAP Applications 15 SP4
  * SUSE Linux Enterprise Server for SAP Applications 15 SP5
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6
  * SUSE Linux Enterprise Server for SAP Applications 15 SP7

  
  
An update that solves nine vulnerabilities and has two security fixes can now be
installed.

## Description:

This update for java-17-openjdk fixes the following issues:

Upgrade to upstream tag jdk-17.0.20+8 (July 2026 CPU).

Security issues fixed:

  * CVE-2026-41254: lcms: information disclosure and denial of service via
    integer overflow in `CubeSize` (bsc#1264994).
  * CVE-2026-46917: unauthenticated attacker with network access via TLS can
    cause a partial denial of service (bsc#1272223).
  * CVE-2026-46968: unauthenticated attacker with network access via TLS can
    gain unauthorized creation, deletion or modification access to critical data
    (bsc#1272224).
  * CVE-2026-47010: unauthenticated attacker with network access via multiple
    protocols can gain unauthorized update, insert or delete access to some data
    (bsc#1272225).
  * CVE-2026-47021: unauthenticated attacker with network access via multiple
    protocols can cause a partial denial of service (bsc#1272227).
  * CVE-2026-47027: unauthenticated attacker with network access via multiple
    protocols can cause a partial denial of service (bsc#1272228).
  * CVE-2026-47059: unauthenticated attacker with network access via multiple
    protocols can cause a partial denial of service (bsc#1272235).
  * CVE-2026-47063: unauthenticated attacker with network access via multiple
    protocols can gain unauthorized creation, deletion or modification access to
    critical data (bsc#1272236).
  * CVE-2026-60147: unauthenticated attacker with network access via multiple
    protocols can gain unauthorized update, insert, delete and read access to
    some data (bsc#1272237).

Other updates and bugfixes:

  * Make post scripts less noisy (bsc#1267355).
  * Use `libalternatives` instead of `update-alternatives` for distributions
    where `libalternatives` is available.
  * Upgrade to upstream tag jdk-17.0.20+8 (July 2026 CPU):
    * JDK-7184899: Test sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fail
    * JDK-8015444: java/awt/Focus/KeyStrokeTest.java sometimes fails
    * JDK-8064922: [macos] Test javax/swing/JTabbedPane/4624207/ /bug4624207.java fails
    * JDK-8068293: [TEST_BUG] Test closed/com/sun/java/swing/plaf/ /motif/InternalFrame/4150591/bug4150591.java fails with GTKLookAndFeel
    * JDK-8068310: [TEST_BUG] Test javax/swing/JColorChooser/ /Test4234761.java fails with GTKL&F
    * JDK-8068378: [TEST_BUG]The java/awt/Modal/PrintDialogsTest/ /PrintDialogsTest.java instruction need to update
    * JDK-8183336: Better cleanup for jdk/test/java/lang/module/ /customfs/ModulesInCustomFileSystem.java
    * JDK-8221451: PIT: sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fails
    * JDK-8240908: RetransformClass does not know about MethodParameters attribute
    * JDK-8255463: java/nio/channels/spi/SelectorProvider/ /inheritedChannel/InheritedChannelTest.java failed with ThreadTimeoutException
    * JDK-8272477: Additional cleanup of test/jdk/java/nio/file/spi/ /SetDefaultProvider.java
    * JDK-8274082: Wrong test name in jtreg run tag for java/awt/ /print/PrinterJob/SwingUIText.java
    * JDK-8277444: Data race between JvmtiClassFileReconstituter::copy_bytecodes and class linking
    * JDK-8281243: Test java/lang/instrument/ /RetransformWithMethodParametersTest.java is failing
    * JDK-8282044: [JVMCI] Export _sha3_implCompress, _md5_implCompress and aarch64::_has_negatives stubs to JVMCI compiler.
    * JDK-8284993: Replace System.exit call in swing tests with RuntimeException
    * JDK-8286258: [Accessibility,macOS,VoiceOver] VoiceOver reads the spinner value wrong and sometime partially
    * JDK-8286865: vmTestbase/vm/mlvm/meth/stress/jni/ /nativeAndMH/Test.java fails with Out of space in CodeCache
    * JDK-8287062: com/sun/jndi/ldap/LdapPoolTimeoutTest.java failed due to different timeout message
    * JDK-8290504: Close streams returned by ModuleReader::list
    * JDK-8293484: AArch64: TestUseSHA512IntrinsicsOptionOnSupportedCPU.java fails on CPU with SHA512 feature support
    * JDK-8297191: [macos] Printing a page range with starting page > 1 results in missing pages
    * JDK-8298783: java/lang/ref/FinalizerHistogramTest.java failed with "RuntimeException: MyObject is not found in test output"
    * JDK-8298823: [macos] java/awt/Mouse/EnterExitEvents/ /DragWindowTest.java continues to fail with "No MouseReleased event on label!"
    * JDK-8299304: Test "java/awt/print/PrinterJob/ /PageDialogTest.java" fails on macOS 13 x64 because the Page Dialog blocks the Toolkit
    * JDK-8304065: HttpServer.stop should terminate immediately if no exchanges are in progress
    * JDK-8309142: Refactor test/langtools/tools/javac/versions/ /Versions.java
    * JDK-8316274: javax/swing/ButtonGroup/ /TestButtonGroupFocusTraversal.java fails in Ubuntu 23.10 with Motif LAF
    * JDK-8317801: java/net/Socket/asyncClose/Race.java fails intermittently (aix)
    * JDK-8320677: Printer tests use invalid '@run main/manual=yesno
    * JDK-8321182: SourceExample.SOURCE_14 comment should refer to 'switch expressions' instead of 'text blocks'
    * JDK-8321303: Intermittent open/test/jdk/java/awt/ /KeyboardFocusmanager/ConsumeNextMnemonicKeyTypedTest/ /ConsumeNextMnemonicKeyTypedTest.java failure on Linux
    * JDK-8323089: networkaddress.cache.ttl is not a system property
    * JDK-8323545: java/awt/GraphicsDevice/CheckDisplayModes.java fails with "exit code: 133"
    * JDK-8323672: Suppress unwanted autoconf added flags in CC and CXX
    * JDK-8324345: Stack overflow during C2 compilation when splitting memory phi
    * JDK-8324641: [IR Framework] Add Setup method to provide custom arguments and set fields
    * JDK-8328300: Convert PrintDialogsTest.java from Applet to main program
    * JDK-8332495: java/util/logging/LoggingDeadlock2.java fails with AssertionError: Some tests failed
    * JDK-8334928: Test sun/security/ssl/SSLSocketImpl/ /ReuseAddr.java failed: java.net.BindException: Address already in use
    * JDK-8337876: [IR Framework] Add support for IR tests with @Stable
    * JDK-8338103: Stabilize and open source a Swing OGL ButtonResizeTest
    * JDK-8338112: Test testlibrary_tests/ir_framework/tests/ /TestPrivilegedMode.java fails with release build
    * JDK-8338344: Test TestPrivilegedMode.java intermittent fails java.lang.NoClassDefFoundError: jdk/test/lib/Platform
    * JDK-8338554: Fix inconsistencies in javadoc/doclet/ /testLinkOption/TestRedirectLinks.java
    * JDK-8338883: Show warning when CreateCoredumpOnCrash set, but core dump will not happen
    * JDK-8339233: Test javax/swing/JButton/ /SwingButtonResizeTestWithOpenGL.java#id failed: Button renderings are different after window resize
    * JDK-8339238: Update to use jtreg 7.5.1
    * JDK-8339879: Open some dialog awt tests
    * JDK-8339975: Open some dialog awt tests 2
    * JDK-8340140: Open some dialog awt tests 3
    * JDK-8340336: Open some checkbox awt tests
    * JDK-8340494: Open some dialog awt tests 4
    * JDK-8340851: Open some TextArea awt tests
    * JDK-8340987: Open some TextArea awt tests 1
    * JDK-8341055: Open some TextArea awt tests 2
    * JDK-8341292: Open some TextArea awt tests 3
    * JDK-8341376: Open some TextArea awt tests 4
    * JDK-8341427: JFR: Adjust object sampler span handling
    * JDK-8342401: [TESTBUG] javax/swing/JSpinner/8223788/ /JSpinnerButtonFocusTest.java test fails in ubuntu 22.04 on SBR Hosts
    * JDK-8345618: javax/swing/text/Caret/8163124/ /CaretFloatingPointAPITest.java leaves Caret is not complete
    * JDK-8346154: [XWayland] Some tests fail intermittently in the CI, but not locally
    * JDK-8347811: Container detection code for cgroups v2 should use cgroup.controllers
    * JDK-8347836: Disabled PopupMenu shows shortcuts on Mac
    * JDK-8349192: jvmti/scenarios/contention/TC05/tc05t001 fails: ERROR: tc05t001.cpp, 281: (waitedThreadCpuTime - waitThreadCpuTime) < (EXPECTED_ACCURACY * 1000000)
    * JDK-8349533: Refactor validator tests shell files to java
    * JDK-8349988: Change cgroup version detection logic to not depend on /proc/cgroups
    * JDK-8350749: Upgrade JLine to 3.29.0
    * JDK-8352685: Opensource JInternalFrame tests - series2
    * JDK-8352733: Improve RotFontBoundsTest test
    * JDK-8352877: Opensource Several Font related tests - Batch 1
    * JDK-8353488: Open some JComboBox bugs 3
    * JDK-8353552: Opensource Several Font related tests - Batch 3
    * JDK-8354163: Open source Swing tests Batch 1
    * JDK-8354469: Keytool exposes the password in plain text when command is piped using | grep
    * JDK-8354695: Open source several swing tests batch7
    * JDK-8354878: File Leak in CgroupSubsystemFactory::determine_type of cgroupSubsystem_linux.cpp:300
    * JDK-8354900: javax/swing/AbstractButton/bug4133768.java failing on macosx-aarch64
    * JDK-8355048: ProblemList TestGlyphVectorLayout.java on all platforms
    * JDK-8355179: Reinstate javax/swing/JScrollBar/4865918/ /bug4865918.java headful and macos run
    * JDK-8355332: Fix failing semi-manual test EDT issue
    * JDK-8355443: [java.io] Use @requires tag instead of exiting based on File.separatorChar value
    * JDK-8355445: [java.nio] Use @requires tag instead of exiting based on "os.name" property value
    * JDK-8356107: [java.lang] Use @requires tag instead of exiting based on os.name or separatorChar property
    * JDK-8357062: Update Public Suffix List to 823beb1
    * JDK-8357082: Stabilize and add debug logs to CopyAreaOOB.java
    * JDK-8357141: Update to use jtreg 7.5.2
    * JDK-8357280: (bf) Remove @requires tags from java/nio/Buffer/ /LimitDirectMemory[NegativeTest].java
    * JDK-8357390: java/awt/Toolkit/ScreenInsetsTest/ /ScreenInsetsTest.java Test failing on Ubuntu 24.04 Vm Hosts used by Oracle's internal CI system
    * JDK-8358058: sun/java2d/OpenGL/DrawImageBg.java Test fails intermittently
    * JDK-8358751: C2: Recursive inlining check for compiled lambda forms is broken
    * JDK-8359978: Test javax/net/ssl/SSLSocket/Tls13PacketSize.java failed again with java.net.SocketException: An established connection was aborted by the software in your host machine
    * JDK-8360160: ubuntu-22-04 machine is failing client tests
    * JDK-8360882: Tests throw SkippedException when they should fail
    * JDK-8361106: [TEST] com/sun/net/httpserver/Test9.java fails with java.nio.file.FileSystemException
    * JDK-8361606: ConsumeNextMnemonicKeyTypedTest.java fails on Windows: character typed with VK_A: a
    * JDK-8362428: Update IANA Language Subtag Registry to Version 2025-08-25
    * JDK-8364190: JFR: RemoteRecordingStream withers don't work
    * JDK-8364315: Remove unused xml files from test/jaxp/javax/xml/ /jaxp/functional/javax/xml/transform/xmlfiles
    * JDK-8364927: Add @requires annotation to TestReclaimStringsLeaksMemory.java
    * JDK-8365379: SU3.applyInsets may produce wrong results
    * JDK-8365423: [macos26] java/awt/MenuBar/8007006/ /bug8007006.java fails on macOS 26
    * JDK-8365424: [macos26] java/awt/Frame/DisposeTest.java fails on macOS 26
    * JDK-8365526: Crash with null Symbol passed to SystemDictionary::resolve_or_null
    * JDK-8365625: Can't change accelerator colors in Windows L&F
    * JDK-8366128: jdk/jdk/nio/zipfs/TestPosix.java::testJarFile uses wrong file
    * JDK-8366261: Provide utility methods for sun.security.util.Password
    * JDK-8366369: Add @requires linux for GTK L&F tests
    * JDK-8366852: java/awt/Choice/ChoiceMouseWheelTest/ /ChoiceMouseWheelTest.java test is failing
    * JDK-8367583: sun/security/util/AlgorithmConstraints/ /InvalidCryptoDisabledAlgos.java fails after JDK-8244336
    * JDK-8367772: Refactor createUI in PassFailJFrame
    * JDK-8367784: java/awt/Focus/InitialFocusTest/ /InitialFocusTest1.java failed with Wrong focus owner
    * JDK-8368041: Enhance TLS certificate handling
    * JDK-8368335: Refactor the rest of Locale TestNG based tests to JUnit
    * JDK-8368498: Use JUnit instead of TestNG for jdk_text tests
    * JDK-8368551: Core dump warning may be confusing
    * JDK-8368670: Deadlock in JFR on event register + class load
    * JDK-8368683: [process] Increase jtreg debug output maxOutputSize for TreeTest
    * JDK-8368754: runtime/cds/appcds/SignedJar.java log regex is too strict
    * JDK-8368885: NMT CommandLine tests can check for error better
    * JDK-8368892: Make JEditorPane/TestBrowserBGColor.java headless
    * JDK-8369251: Opensource few tests
    * JDK-8369319: java/net/httpclient/CancelRequestTest.java fails intermittently
    * JDK-8369335: Two sun/java2d/OpenGL tests fail on Windows after JDK-8358058
    * JDK-8369561: sun/java2d/OpenGL/DrawBitmaskImage.java#id0: Incorrect color for first pixel (actual=ff000000)
    * JDK-8369851: Remove darcy author tags from langtools tests
    * JDK-8369858: Remove darcy author tags from jdk tests
    * JDK-8369911: Test sun/java2d/marlin/ClipShapeTest.java #CubicDoDash, #Cubic and #Poly fail intermittent
    * JDK-8369950: TLS connection to IPv6 address fails with BCJSSE due to IllegalArgumentException
    * JDK-8370325: G1: Disallow GC for TLAB allocation
    * JDK-8370511: test/jdk/javax/swing/JSlider/bug4382876.java does not release previously pressed keys
    * JDK-8370732: Use WhiteBox.getWhiteBox().fullGC() to provoking gc for nsk/jvmti tests
    * JDK-8370942: test/jdk/java/security/Provider/NewInstance.java and /test/jdk/java/security/cert/CertStore/NoLDAP.java may skip without notifying
    * JDK-8371365: Update javax/swing/JFileChooser/bug4759934.java to use Util.findComponent()
    * JDK-8371366: java/net/httpclient/whitebox/ /RawChannelTestDriver.java fails intermittently in jtreg timeout
    * JDK-8371383: Test sun/security/tools/jarsigner/ /DefaultOptions.java failed due to CertificateNotYetValidException
    * JDK-8371503: RETAIN_IMAGE_AFTER_TEST do not work for some tests
    * JDK-8372120: Add missing sound keyword to MIDI tests
    * JDK-8372351: Add 2 WISeKey roots
    * JDK-8372609: Bug4944439 does not enforce locale correctly
    * JDK-8372661: Add a null-safe static factory method to "jdk.test.lib.net.SimpleSSLContext"
    * JDK-8372988: Test runtime/Nestmates/membership/ /TestNestHostErrorWithMultiThread.java failed: Unexpected interrupt
    * JDK-8373101: JdkClient and JdkServer test classes ignore namedGroups field
    * JDK-8373239: Test java/awt/print/PrinterJob/PageRanges.java fails with incorrect selection of printed pages
    * JDK-8373275: Improve DTLS handshaking
    * JDK-8373623: Refactor Serialization tests for Records to JUnit
    * JDK-8373650: Test "javax/swing/JMenuItem/6458123/ /ManualBug6458123.java" fails because the check icons are not aligned properly as expected
    * JDK-8373690: Unexpected Keystore message using jdk.crypto.disabledAlgorithms
    * JDK-8373716: Refactor further java/util tests from TestNG to JUnit
    * JDK-8373807: test/jdk/java/net/httpclient/websocket/ /DummyWebSocketServer.java getURI() uses "localhost"
    * JDK-8373847: Test javax/swing/JMenuItem/MenuItemTest/ /bug6197830.java failed because The test case automatically fails when clicking any items in the “Nothing” menu in all four windows (Left-to-right)-Menu Item Test and (Right-to-left)-Menu Item Test
    * JDK-8373869: Refactor java/net/httpclient/ /ThrowingPushPromises*.java tests to use JUnit5
    * JDK-8373928: 4 Dangling pointer defect groups in java.c
    * JDK-8373931: Test javax/sound/sampled/Clip/ /AutoCloseTimeCheck.java timed out
    * JDK-8374058: Enhance JPEG handling
    * JDK-8374178: Missing include in systemDictionary.cpp after JDK-8365526
    * JDK-8374304: MultiResolutionSplashTest.java fails in CI: "Image with wrong resolution is used for splash screen!"
    * JDK-8374433: java/util/Locale/PreserveTagCase.java does not run any tests
    * JDK-8374506: Incorrect positioning of arrow icon in parent JMenu in Windows L&F
    * JDK-8374548: Process httpserver cancelled keys more quickly
    * JDK-8374555: No need for visible input warning in s.s.u.Password when not reading from System.in
    * JDK-8374711: Hotspot runtime/CommandLine/OptionsValidation/ /TestOptionsWithRanges fails without printing the option name
    * JDK-8374888: Implement internal test cache to help UserIterCount test performance
    * JDK-8374998: Failing os::write - remove bad file
    * JDK-8375065: Update LCMS to 2.18
    * JDK-8375080: The tools/jpackage/windows/Win8365790Test.java may fail with ClassNotFoundException: jtreg.SkippedException
    * JDK-8375231: Refactor util/ServiceLoader tests to use JUnit
    * JDK-8375232: Refactor util/StringJoiner tests to use JUnit
    * JDK-8375233: Refactor util/Vector tests to use JUnit
    * JDK-8375999: com/sun/jndi/ldap/LdapPoolTimeoutTest.java fails sporadically on Windows
    * JDK-8376031: HttpsURLConnection.getServerCertificates() throws "java.lang.IllegalStateException: connection not yet open" for the HEAD method
    * JDK-8376152: Test javax/sound/sampled/Clip/bug5070081.java timed out then completed
    * JDK-8376233: Clean up code in Desktop native peer
    * JDK-8377158: Enhance XBM image support
    * JDK-8377167: javax/imageio/ReadAbortTest.java throw NPE when x11 unavailable
    * JDK-8377498: Improve HttpServer handling
    * JDK-8377602: Create automated test for PageRange
    * JDK-8377678: G1: Heap Dumping crashes with -UseClassUnloading
    * JDK-8377727: Ghost caret and focus appear in non‑editable text fields
    * JDK-8377833: Enhance Jar file processing
    * JDK-8377910: Minor cleanup of java/io/FileDescriptor/ /Sharing.java
    * JDK-8377944: LowMemoryTest2.java#id1 intermittent fails OOME: Metaspace
    * JDK-8378113: Add sun/java2d/OpenGL/ScaleParamsOOB.java to the ProblemList.txt file
    * JDK-8378201: [OGL] glXMakeContextCurrent() drops the buffers of the unbound drawable
    * JDK-8378417: Printing All pages results in NPE for 1.1 PrintJob
    * JDK-8378687: Improve delegation of HttpURLConnection
    * JDK-8378777: Bump update version for OpenJDK: jdk-17.0.20
    * JDK-8378802: [21u] backport changes to TKit.java by JDK-8352419
    * JDK-8380316: Test runtime/os/AvailableProcessors.java fails Invalid argument
    * JDK-8380565: PPC64: deoptimization stub should save vector registers
    * JDK-8380672: Improve certification checking
    * JDK-8380947: Add pull request template
    * JDK-8381039: Enhance AWT ImagingLib
    * JDK-8381049: Enhance Jar handling
    * JDK-8381205: GHA: Upgrade Node.js 20 to 24
    * JDK-8381519: Enhance Der Value Handling
    * JDK-8381796: Enhance Certificate parsing
    * JDK-8382242: JFR: Metadata reconstruction invalidates ConstantMap for java.lang.String
    * JDK-8383175: (tz) Update Timezone Data to 2026b
    * JDK-8383354: Update LCMS to 2.19.1
    * JDK-8383473: Follow on from tzdata2026b time change to include temporary hack BC time change
    * JDK-8383601: RISC-V: ShenandoahBarrierSetAssembler::load_reference_barrier calls "weak" on "phantom" path
    * JDK-8383630: Fix iteration in tests doing class redefinition
    * JDK-8383659: [17u] JVM crashes during stub routines generation on Windows and rare combination of CPU features
    * JDK-8384158: GHA: Downgrade Windows GHA runners to windows-2022 temporarily
    * JDK-8384486: NTLM tests fail on Windows 11 and Windows Server 2025
    * JDK-8384495: Update Libpng to 1.6.58
    * JDK-8384540: [25u, 21u, 17u] Update GHA JDKs after Apr/26 updates
    * JDK-8384815: SelectOneKeyOutOfMany and PreferredKey fail after expired test certificate
    * JDK-8384902: Update GIFlib to 6.1.3
    * JDK-8385390: Update FreeType to 2.14.3
    * JDK-8385490: Update HarfBuzz to 14.2.0
    * JDK-8386343: [17u] Fix NTLMHeadTest after backport of 8384486
    * JDK-8386551: Windows build broken because of MSys2/Make update

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server 15 SP4 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3406=1

  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3406=1

  * openSUSE Leap 15.4  
    zypper in -t patch SUSE-2026-3406=1

  * SUSE Linux Enterprise Server for SAP Applications 15 SP6  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3406=1

  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3406=1

  * SUSE Linux Enterprise Server 15 SP6 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3406=1

  * SUSE Linux Enterprise Server for SAP Applications 15 SP5  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3406=1

  * Legacy Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-3406=1

  * SUSE Linux Enterprise Server for SAP Applications 15 SP4  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3406=1

  * SUSE Linux Enterprise Server 15 SP5 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3406=1

  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3406=1

  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3406=1

## Package List:

  * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64)
    * java-17-openjdk-demo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
    * java-17-openjdk-demo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
  * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
    * java-17-openjdk-demo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-jmods-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-17.0.20.0-150400.3.69.1
    * java-17-openjdk-src-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
  * openSUSE Leap 15.4 (noarch)
    * java-17-openjdk-javadoc-17.0.20.0-150400.3.69.1
  * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
    * java-17-openjdk-demo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
    x86_64)
    * java-17-openjdk-demo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
    * java-17-openjdk-demo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
    x86_64)
    * java-17-openjdk-demo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
  * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
    * java-17-openjdk-demo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
  * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
    * java-17-openjdk-demo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
    * java-17-openjdk-demo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
    x86_64)
    * java-17-openjdk-demo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
    x86_64)
    * java-17-openjdk-demo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-17.0.20.0-150400.3.69.1
    * java-17-openjdk-headless-17.0.20.0-150400.3.69.1
    * java-17-openjdk-devel-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
    * java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1

## References:

  * https://www.suse.com/security/cve/CVE-2026-41254.html
  * https://www.suse.com/security/cve/CVE-2026-46917.html
  * https://www.suse.com/security/cve/CVE-2026-46968.html
  * https://www.suse.com/security/cve/CVE-2026-47010.html
  * https://www.suse.com/security/cve/CVE-2026-47021.html
  * https://www.suse.com/security/cve/CVE-2026-47027.html
  * https://www.suse.com/security/cve/CVE-2026-47059.html
  * https://www.suse.com/security/cve/CVE-2026-47063.html
  * https://www.suse.com/security/cve/CVE-2026-60147.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1264396
  * https://bugzilla.suse.com/show_bug.cgi?id=1264994
  * https://bugzilla.suse.com/show_bug.cgi?id=1267355
  * https://bugzilla.suse.com/show_bug.cgi?id=1272223
  * https://bugzilla.suse.com/show_bug.cgi?id=1272224
  * https://bugzilla.suse.com/show_bug.cgi?id=1272225
  * https://bugzilla.suse.com/show_bug.cgi?id=1272227
  * https://bugzilla.suse.com/show_bug.cgi?id=1272228
  * https://bugzilla.suse.com/show_bug.cgi?id=1272235
  * https://bugzilla.suse.com/show_bug.cgi?id=1272236
  * https://bugzilla.suse.com/show_bug.cgi?id=1272237

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260729/71fe496e/attachment.htm>


More information about the sle-updates mailing list