SUSE-SU-2026:3406-1: important: Security update for java-17-openjdk
SLE-UPDATES
null at suse.de
Wed Jul 29 16:33:31 UTC 2026
# Security update for java-17-openjdk
Announcement ID: SUSE-SU-2026:3406-1
Release Date: 2026-07-29T11:10:17Z
Rating: important
References:
* bsc#1264396
* bsc#1264994
* bsc#1267355
* bsc#1272223
* bsc#1272224
* bsc#1272225
* bsc#1272227
* bsc#1272228
* bsc#1272235
* bsc#1272236
* bsc#1272237
Cross-References:
* CVE-2026-41254
* CVE-2026-46917
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47021
* CVE-2026-47027
* CVE-2026-47059
* CVE-2026-47063
* CVE-2026-60147
CVSS scores:
* CVE-2026-41254 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-46917 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46917 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46968 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-47010 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47021 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47063 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-47063 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-60147 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-60147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products:
* Legacy Module 15-SP7
* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves nine vulnerabilities and has two security fixes can now be
installed.
## Description:
This update for java-17-openjdk fixes the following issues:
Upgrade to upstream tag jdk-17.0.20+8 (July 2026 CPU).
Security issues fixed:
* CVE-2026-41254: lcms: information disclosure and denial of service via
integer overflow in `CubeSize` (bsc#1264994).
* CVE-2026-46917: unauthenticated attacker with network access via TLS can
cause a partial denial of service (bsc#1272223).
* CVE-2026-46968: unauthenticated attacker with network access via TLS can
gain unauthorized creation, deletion or modification access to critical data
(bsc#1272224).
* CVE-2026-47010: unauthenticated attacker with network access via multiple
protocols can gain unauthorized update, insert or delete access to some data
(bsc#1272225).
* CVE-2026-47021: unauthenticated attacker with network access via multiple
protocols can cause a partial denial of service (bsc#1272227).
* CVE-2026-47027: unauthenticated attacker with network access via multiple
protocols can cause a partial denial of service (bsc#1272228).
* CVE-2026-47059: unauthenticated attacker with network access via multiple
protocols can cause a partial denial of service (bsc#1272235).
* CVE-2026-47063: unauthenticated attacker with network access via multiple
protocols can gain unauthorized creation, deletion or modification access to
critical data (bsc#1272236).
* CVE-2026-60147: unauthenticated attacker with network access via multiple
protocols can gain unauthorized update, insert, delete and read access to
some data (bsc#1272237).
Other updates and bugfixes:
* Make post scripts less noisy (bsc#1267355).
* Use `libalternatives` instead of `update-alternatives` for distributions
where `libalternatives` is available.
* Upgrade to upstream tag jdk-17.0.20+8 (July 2026 CPU):
* JDK-7184899: Test sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fail
* JDK-8015444: java/awt/Focus/KeyStrokeTest.java sometimes fails
* JDK-8064922: [macos] Test javax/swing/JTabbedPane/4624207/ /bug4624207.java fails
* JDK-8068293: [TEST_BUG] Test closed/com/sun/java/swing/plaf/ /motif/InternalFrame/4150591/bug4150591.java fails with GTKLookAndFeel
* JDK-8068310: [TEST_BUG] Test javax/swing/JColorChooser/ /Test4234761.java fails with GTKL&F
* JDK-8068378: [TEST_BUG]The java/awt/Modal/PrintDialogsTest/ /PrintDialogsTest.java instruction need to update
* JDK-8183336: Better cleanup for jdk/test/java/lang/module/ /customfs/ModulesInCustomFileSystem.java
* JDK-8221451: PIT: sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fails
* JDK-8240908: RetransformClass does not know about MethodParameters attribute
* JDK-8255463: java/nio/channels/spi/SelectorProvider/ /inheritedChannel/InheritedChannelTest.java failed with ThreadTimeoutException
* JDK-8272477: Additional cleanup of test/jdk/java/nio/file/spi/ /SetDefaultProvider.java
* JDK-8274082: Wrong test name in jtreg run tag for java/awt/ /print/PrinterJob/SwingUIText.java
* JDK-8277444: Data race between JvmtiClassFileReconstituter::copy_bytecodes and class linking
* JDK-8281243: Test java/lang/instrument/ /RetransformWithMethodParametersTest.java is failing
* JDK-8282044: [JVMCI] Export _sha3_implCompress, _md5_implCompress and aarch64::_has_negatives stubs to JVMCI compiler.
* JDK-8284993: Replace System.exit call in swing tests with RuntimeException
* JDK-8286258: [Accessibility,macOS,VoiceOver] VoiceOver reads the spinner value wrong and sometime partially
* JDK-8286865: vmTestbase/vm/mlvm/meth/stress/jni/ /nativeAndMH/Test.java fails with Out of space in CodeCache
* JDK-8287062: com/sun/jndi/ldap/LdapPoolTimeoutTest.java failed due to different timeout message
* JDK-8290504: Close streams returned by ModuleReader::list
* JDK-8293484: AArch64: TestUseSHA512IntrinsicsOptionOnSupportedCPU.java fails on CPU with SHA512 feature support
* JDK-8297191: [macos] Printing a page range with starting page > 1 results in missing pages
* JDK-8298783: java/lang/ref/FinalizerHistogramTest.java failed with "RuntimeException: MyObject is not found in test output"
* JDK-8298823: [macos] java/awt/Mouse/EnterExitEvents/ /DragWindowTest.java continues to fail with "No MouseReleased event on label!"
* JDK-8299304: Test "java/awt/print/PrinterJob/ /PageDialogTest.java" fails on macOS 13 x64 because the Page Dialog blocks the Toolkit
* JDK-8304065: HttpServer.stop should terminate immediately if no exchanges are in progress
* JDK-8309142: Refactor test/langtools/tools/javac/versions/ /Versions.java
* JDK-8316274: javax/swing/ButtonGroup/ /TestButtonGroupFocusTraversal.java fails in Ubuntu 23.10 with Motif LAF
* JDK-8317801: java/net/Socket/asyncClose/Race.java fails intermittently (aix)
* JDK-8320677: Printer tests use invalid '@run main/manual=yesno
* JDK-8321182: SourceExample.SOURCE_14 comment should refer to 'switch expressions' instead of 'text blocks'
* JDK-8321303: Intermittent open/test/jdk/java/awt/ /KeyboardFocusmanager/ConsumeNextMnemonicKeyTypedTest/ /ConsumeNextMnemonicKeyTypedTest.java failure on Linux
* JDK-8323089: networkaddress.cache.ttl is not a system property
* JDK-8323545: java/awt/GraphicsDevice/CheckDisplayModes.java fails with "exit code: 133"
* JDK-8323672: Suppress unwanted autoconf added flags in CC and CXX
* JDK-8324345: Stack overflow during C2 compilation when splitting memory phi
* JDK-8324641: [IR Framework] Add Setup method to provide custom arguments and set fields
* JDK-8328300: Convert PrintDialogsTest.java from Applet to main program
* JDK-8332495: java/util/logging/LoggingDeadlock2.java fails with AssertionError: Some tests failed
* JDK-8334928: Test sun/security/ssl/SSLSocketImpl/ /ReuseAddr.java failed: java.net.BindException: Address already in use
* JDK-8337876: [IR Framework] Add support for IR tests with @Stable
* JDK-8338103: Stabilize and open source a Swing OGL ButtonResizeTest
* JDK-8338112: Test testlibrary_tests/ir_framework/tests/ /TestPrivilegedMode.java fails with release build
* JDK-8338344: Test TestPrivilegedMode.java intermittent fails java.lang.NoClassDefFoundError: jdk/test/lib/Platform
* JDK-8338554: Fix inconsistencies in javadoc/doclet/ /testLinkOption/TestRedirectLinks.java
* JDK-8338883: Show warning when CreateCoredumpOnCrash set, but core dump will not happen
* JDK-8339233: Test javax/swing/JButton/ /SwingButtonResizeTestWithOpenGL.java#id failed: Button renderings are different after window resize
* JDK-8339238: Update to use jtreg 7.5.1
* JDK-8339879: Open some dialog awt tests
* JDK-8339975: Open some dialog awt tests 2
* JDK-8340140: Open some dialog awt tests 3
* JDK-8340336: Open some checkbox awt tests
* JDK-8340494: Open some dialog awt tests 4
* JDK-8340851: Open some TextArea awt tests
* JDK-8340987: Open some TextArea awt tests 1
* JDK-8341055: Open some TextArea awt tests 2
* JDK-8341292: Open some TextArea awt tests 3
* JDK-8341376: Open some TextArea awt tests 4
* JDK-8341427: JFR: Adjust object sampler span handling
* JDK-8342401: [TESTBUG] javax/swing/JSpinner/8223788/ /JSpinnerButtonFocusTest.java test fails in ubuntu 22.04 on SBR Hosts
* JDK-8345618: javax/swing/text/Caret/8163124/ /CaretFloatingPointAPITest.java leaves Caret is not complete
* JDK-8346154: [XWayland] Some tests fail intermittently in the CI, but not locally
* JDK-8347811: Container detection code for cgroups v2 should use cgroup.controllers
* JDK-8347836: Disabled PopupMenu shows shortcuts on Mac
* JDK-8349192: jvmti/scenarios/contention/TC05/tc05t001 fails: ERROR: tc05t001.cpp, 281: (waitedThreadCpuTime - waitThreadCpuTime) < (EXPECTED_ACCURACY * 1000000)
* JDK-8349533: Refactor validator tests shell files to java
* JDK-8349988: Change cgroup version detection logic to not depend on /proc/cgroups
* JDK-8350749: Upgrade JLine to 3.29.0
* JDK-8352685: Opensource JInternalFrame tests - series2
* JDK-8352733: Improve RotFontBoundsTest test
* JDK-8352877: Opensource Several Font related tests - Batch 1
* JDK-8353488: Open some JComboBox bugs 3
* JDK-8353552: Opensource Several Font related tests - Batch 3
* JDK-8354163: Open source Swing tests Batch 1
* JDK-8354469: Keytool exposes the password in plain text when command is piped using | grep
* JDK-8354695: Open source several swing tests batch7
* JDK-8354878: File Leak in CgroupSubsystemFactory::determine_type of cgroupSubsystem_linux.cpp:300
* JDK-8354900: javax/swing/AbstractButton/bug4133768.java failing on macosx-aarch64
* JDK-8355048: ProblemList TestGlyphVectorLayout.java on all platforms
* JDK-8355179: Reinstate javax/swing/JScrollBar/4865918/ /bug4865918.java headful and macos run
* JDK-8355332: Fix failing semi-manual test EDT issue
* JDK-8355443: [java.io] Use @requires tag instead of exiting based on File.separatorChar value
* JDK-8355445: [java.nio] Use @requires tag instead of exiting based on "os.name" property value
* JDK-8356107: [java.lang] Use @requires tag instead of exiting based on os.name or separatorChar property
* JDK-8357062: Update Public Suffix List to 823beb1
* JDK-8357082: Stabilize and add debug logs to CopyAreaOOB.java
* JDK-8357141: Update to use jtreg 7.5.2
* JDK-8357280: (bf) Remove @requires tags from java/nio/Buffer/ /LimitDirectMemory[NegativeTest].java
* JDK-8357390: java/awt/Toolkit/ScreenInsetsTest/ /ScreenInsetsTest.java Test failing on Ubuntu 24.04 Vm Hosts used by Oracle's internal CI system
* JDK-8358058: sun/java2d/OpenGL/DrawImageBg.java Test fails intermittently
* JDK-8358751: C2: Recursive inlining check for compiled lambda forms is broken
* JDK-8359978: Test javax/net/ssl/SSLSocket/Tls13PacketSize.java failed again with java.net.SocketException: An established connection was aborted by the software in your host machine
* JDK-8360160: ubuntu-22-04 machine is failing client tests
* JDK-8360882: Tests throw SkippedException when they should fail
* JDK-8361106: [TEST] com/sun/net/httpserver/Test9.java fails with java.nio.file.FileSystemException
* JDK-8361606: ConsumeNextMnemonicKeyTypedTest.java fails on Windows: character typed with VK_A: a
* JDK-8362428: Update IANA Language Subtag Registry to Version 2025-08-25
* JDK-8364190: JFR: RemoteRecordingStream withers don't work
* JDK-8364315: Remove unused xml files from test/jaxp/javax/xml/ /jaxp/functional/javax/xml/transform/xmlfiles
* JDK-8364927: Add @requires annotation to TestReclaimStringsLeaksMemory.java
* JDK-8365379: SU3.applyInsets may produce wrong results
* JDK-8365423: [macos26] java/awt/MenuBar/8007006/ /bug8007006.java fails on macOS 26
* JDK-8365424: [macos26] java/awt/Frame/DisposeTest.java fails on macOS 26
* JDK-8365526: Crash with null Symbol passed to SystemDictionary::resolve_or_null
* JDK-8365625: Can't change accelerator colors in Windows L&F
* JDK-8366128: jdk/jdk/nio/zipfs/TestPosix.java::testJarFile uses wrong file
* JDK-8366261: Provide utility methods for sun.security.util.Password
* JDK-8366369: Add @requires linux for GTK L&F tests
* JDK-8366852: java/awt/Choice/ChoiceMouseWheelTest/ /ChoiceMouseWheelTest.java test is failing
* JDK-8367583: sun/security/util/AlgorithmConstraints/ /InvalidCryptoDisabledAlgos.java fails after JDK-8244336
* JDK-8367772: Refactor createUI in PassFailJFrame
* JDK-8367784: java/awt/Focus/InitialFocusTest/ /InitialFocusTest1.java failed with Wrong focus owner
* JDK-8368041: Enhance TLS certificate handling
* JDK-8368335: Refactor the rest of Locale TestNG based tests to JUnit
* JDK-8368498: Use JUnit instead of TestNG for jdk_text tests
* JDK-8368551: Core dump warning may be confusing
* JDK-8368670: Deadlock in JFR on event register + class load
* JDK-8368683: [process] Increase jtreg debug output maxOutputSize for TreeTest
* JDK-8368754: runtime/cds/appcds/SignedJar.java log regex is too strict
* JDK-8368885: NMT CommandLine tests can check for error better
* JDK-8368892: Make JEditorPane/TestBrowserBGColor.java headless
* JDK-8369251: Opensource few tests
* JDK-8369319: java/net/httpclient/CancelRequestTest.java fails intermittently
* JDK-8369335: Two sun/java2d/OpenGL tests fail on Windows after JDK-8358058
* JDK-8369561: sun/java2d/OpenGL/DrawBitmaskImage.java#id0: Incorrect color for first pixel (actual=ff000000)
* JDK-8369851: Remove darcy author tags from langtools tests
* JDK-8369858: Remove darcy author tags from jdk tests
* JDK-8369911: Test sun/java2d/marlin/ClipShapeTest.java #CubicDoDash, #Cubic and #Poly fail intermittent
* JDK-8369950: TLS connection to IPv6 address fails with BCJSSE due to IllegalArgumentException
* JDK-8370325: G1: Disallow GC for TLAB allocation
* JDK-8370511: test/jdk/javax/swing/JSlider/bug4382876.java does not release previously pressed keys
* JDK-8370732: Use WhiteBox.getWhiteBox().fullGC() to provoking gc for nsk/jvmti tests
* JDK-8370942: test/jdk/java/security/Provider/NewInstance.java and /test/jdk/java/security/cert/CertStore/NoLDAP.java may skip without notifying
* JDK-8371365: Update javax/swing/JFileChooser/bug4759934.java to use Util.findComponent()
* JDK-8371366: java/net/httpclient/whitebox/ /RawChannelTestDriver.java fails intermittently in jtreg timeout
* JDK-8371383: Test sun/security/tools/jarsigner/ /DefaultOptions.java failed due to CertificateNotYetValidException
* JDK-8371503: RETAIN_IMAGE_AFTER_TEST do not work for some tests
* JDK-8372120: Add missing sound keyword to MIDI tests
* JDK-8372351: Add 2 WISeKey roots
* JDK-8372609: Bug4944439 does not enforce locale correctly
* JDK-8372661: Add a null-safe static factory method to "jdk.test.lib.net.SimpleSSLContext"
* JDK-8372988: Test runtime/Nestmates/membership/ /TestNestHostErrorWithMultiThread.java failed: Unexpected interrupt
* JDK-8373101: JdkClient and JdkServer test classes ignore namedGroups field
* JDK-8373239: Test java/awt/print/PrinterJob/PageRanges.java fails with incorrect selection of printed pages
* JDK-8373275: Improve DTLS handshaking
* JDK-8373623: Refactor Serialization tests for Records to JUnit
* JDK-8373650: Test "javax/swing/JMenuItem/6458123/ /ManualBug6458123.java" fails because the check icons are not aligned properly as expected
* JDK-8373690: Unexpected Keystore message using jdk.crypto.disabledAlgorithms
* JDK-8373716: Refactor further java/util tests from TestNG to JUnit
* JDK-8373807: test/jdk/java/net/httpclient/websocket/ /DummyWebSocketServer.java getURI() uses "localhost"
* JDK-8373847: Test javax/swing/JMenuItem/MenuItemTest/ /bug6197830.java failed because The test case automatically fails when clicking any items in the “Nothing” menu in all four windows (Left-to-right)-Menu Item Test and (Right-to-left)-Menu Item Test
* JDK-8373869: Refactor java/net/httpclient/ /ThrowingPushPromises*.java tests to use JUnit5
* JDK-8373928: 4 Dangling pointer defect groups in java.c
* JDK-8373931: Test javax/sound/sampled/Clip/ /AutoCloseTimeCheck.java timed out
* JDK-8374058: Enhance JPEG handling
* JDK-8374178: Missing include in systemDictionary.cpp after JDK-8365526
* JDK-8374304: MultiResolutionSplashTest.java fails in CI: "Image with wrong resolution is used for splash screen!"
* JDK-8374433: java/util/Locale/PreserveTagCase.java does not run any tests
* JDK-8374506: Incorrect positioning of arrow icon in parent JMenu in Windows L&F
* JDK-8374548: Process httpserver cancelled keys more quickly
* JDK-8374555: No need for visible input warning in s.s.u.Password when not reading from System.in
* JDK-8374711: Hotspot runtime/CommandLine/OptionsValidation/ /TestOptionsWithRanges fails without printing the option name
* JDK-8374888: Implement internal test cache to help UserIterCount test performance
* JDK-8374998: Failing os::write - remove bad file
* JDK-8375065: Update LCMS to 2.18
* JDK-8375080: The tools/jpackage/windows/Win8365790Test.java may fail with ClassNotFoundException: jtreg.SkippedException
* JDK-8375231: Refactor util/ServiceLoader tests to use JUnit
* JDK-8375232: Refactor util/StringJoiner tests to use JUnit
* JDK-8375233: Refactor util/Vector tests to use JUnit
* JDK-8375999: com/sun/jndi/ldap/LdapPoolTimeoutTest.java fails sporadically on Windows
* JDK-8376031: HttpsURLConnection.getServerCertificates() throws "java.lang.IllegalStateException: connection not yet open" for the HEAD method
* JDK-8376152: Test javax/sound/sampled/Clip/bug5070081.java timed out then completed
* JDK-8376233: Clean up code in Desktop native peer
* JDK-8377158: Enhance XBM image support
* JDK-8377167: javax/imageio/ReadAbortTest.java throw NPE when x11 unavailable
* JDK-8377498: Improve HttpServer handling
* JDK-8377602: Create automated test for PageRange
* JDK-8377678: G1: Heap Dumping crashes with -UseClassUnloading
* JDK-8377727: Ghost caret and focus appear in non‑editable text fields
* JDK-8377833: Enhance Jar file processing
* JDK-8377910: Minor cleanup of java/io/FileDescriptor/ /Sharing.java
* JDK-8377944: LowMemoryTest2.java#id1 intermittent fails OOME: Metaspace
* JDK-8378113: Add sun/java2d/OpenGL/ScaleParamsOOB.java to the ProblemList.txt file
* JDK-8378201: [OGL] glXMakeContextCurrent() drops the buffers of the unbound drawable
* JDK-8378417: Printing All pages results in NPE for 1.1 PrintJob
* JDK-8378687: Improve delegation of HttpURLConnection
* JDK-8378777: Bump update version for OpenJDK: jdk-17.0.20
* JDK-8378802: [21u] backport changes to TKit.java by JDK-8352419
* JDK-8380316: Test runtime/os/AvailableProcessors.java fails Invalid argument
* JDK-8380565: PPC64: deoptimization stub should save vector registers
* JDK-8380672: Improve certification checking
* JDK-8380947: Add pull request template
* JDK-8381039: Enhance AWT ImagingLib
* JDK-8381049: Enhance Jar handling
* JDK-8381205: GHA: Upgrade Node.js 20 to 24
* JDK-8381519: Enhance Der Value Handling
* JDK-8381796: Enhance Certificate parsing
* JDK-8382242: JFR: Metadata reconstruction invalidates ConstantMap for java.lang.String
* JDK-8383175: (tz) Update Timezone Data to 2026b
* JDK-8383354: Update LCMS to 2.19.1
* JDK-8383473: Follow on from tzdata2026b time change to include temporary hack BC time change
* JDK-8383601: RISC-V: ShenandoahBarrierSetAssembler::load_reference_barrier calls "weak" on "phantom" path
* JDK-8383630: Fix iteration in tests doing class redefinition
* JDK-8383659: [17u] JVM crashes during stub routines generation on Windows and rare combination of CPU features
* JDK-8384158: GHA: Downgrade Windows GHA runners to windows-2022 temporarily
* JDK-8384486: NTLM tests fail on Windows 11 and Windows Server 2025
* JDK-8384495: Update Libpng to 1.6.58
* JDK-8384540: [25u, 21u, 17u] Update GHA JDKs after Apr/26 updates
* JDK-8384815: SelectOneKeyOutOfMany and PreferredKey fail after expired test certificate
* JDK-8384902: Update GIFlib to 6.1.3
* JDK-8385390: Update FreeType to 2.14.3
* JDK-8385490: Update HarfBuzz to 14.2.0
* JDK-8386343: [17u] Fix NTLMHeadTest after backport of 8384486
* JDK-8386551: Windows build broken because of MSys2/Make update
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3406=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3406=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3406=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3406=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3406=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3406=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3406=1
* Legacy Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-3406=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3406=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3406=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3406=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3406=1
## Package List:
* Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-jmods-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-src-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* openSUSE Leap 15.4 (noarch)
* java-17-openjdk-javadoc-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
## References:
* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46917.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47021.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47059.html
* https://www.suse.com/security/cve/CVE-2026-47063.html
* https://www.suse.com/security/cve/CVE-2026-60147.html
* https://bugzilla.suse.com/show_bug.cgi?id=1264396
* https://bugzilla.suse.com/show_bug.cgi?id=1264994
* https://bugzilla.suse.com/show_bug.cgi?id=1267355
* https://bugzilla.suse.com/show_bug.cgi?id=1272223
* https://bugzilla.suse.com/show_bug.cgi?id=1272224
* https://bugzilla.suse.com/show_bug.cgi?id=1272225
* https://bugzilla.suse.com/show_bug.cgi?id=1272227
* https://bugzilla.suse.com/show_bug.cgi?id=1272228
* https://bugzilla.suse.com/show_bug.cgi?id=1272235
* https://bugzilla.suse.com/show_bug.cgi?id=1272236
* https://bugzilla.suse.com/show_bug.cgi?id=1272237
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260729/71fe496e/attachment.htm>
More information about the sle-updates
mailing list