[CLSA-2025:1754649468] Fix of 5 CVEs
Type:
security
Severity:
Important
Release date:
2025-08-08 10:38:04 UTC
Description:
* OpenJDK 11.0.28 release, build 6. - CVE-2025-30749: Java 2D heap corruption, code execution/DoS - CVE-2025-30754: JSSE TLS handshake flaw, weakened encryption - CVE-2025-30761: nashorn sandbox bypass, code execution - CVE-2025-50059: HTTP client header bug, data leak - CVE-2025-50106: Glyph rendering memory bug, crash/code exec - Release notes: https://mail.openjdk.org/pipermail/jdk-updates-dev/2025-July/045612.html
Updated packages:
  • openjdk-11-demo_11.0.28+6-0ubuntu1~18.04.1+tuxcare.els1_amd64.deb
    sha:877e731234e54a49ef52c2e990ef615c8965bb13
  • openjdk-11-doc_11.0.28+6-0ubuntu1~18.04.1+tuxcare.els1_all.deb
    sha:36a85fa7c728820887fc733f23e0f0101dd2041a
  • openjdk-11-jdk_11.0.28+6-0ubuntu1~18.04.1+tuxcare.els1_amd64.deb
    sha:40eb5f399568b0657827cd29de445aa5b76baed4
  • openjdk-11-jdk-headless_11.0.28+6-0ubuntu1~18.04.1+tuxcare.els1_amd64.deb
    sha:55f1454600b217c41c3f63581f67623e6a2e0a72
  • openjdk-11-jre_11.0.28+6-0ubuntu1~18.04.1+tuxcare.els1_amd64.deb
    sha:167e79df1cb2526284ef728fe08177b4f61086c0
  • openjdk-11-jre-headless_11.0.28+6-0ubuntu1~18.04.1+tuxcare.els1_amd64.deb
    sha:7f2915ff7f8caec8d40f345a2493ea4c826fda2b
  • openjdk-11-jre-zero_11.0.28+6-0ubuntu1~18.04.1+tuxcare.els1_amd64.deb
    sha:0fc0490f19d6d2e3e61da756c534b684baddc5b8
  • openjdk-11-source_11.0.28+6-0ubuntu1~18.04.1+tuxcare.els1_all.deb
    sha:64cee9e2a2888f7b0f3667092cf950ca1d0a23af
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.