UNKNOWNAlmaLinux:10 →
Important: java-25-openjdk security update
Important: java-25-openjdk security update
Affected packages
- java-25-openjdk— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-crypto-adapter— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-crypto-adapter-fastdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-crypto-adapter-slowdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-demo— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-demo-fastdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-demo-slowdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-devel— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-devel-fastdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-devel-slowdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-fastdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-headless— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-headless-fastdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-headless-slowdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-javadoc— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-javadoc-zip— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-jmods— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-jmods-fastdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-jmods-slowdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-slowdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-src— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-src-fastdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-src-slowdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-static-libs— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-static-libs-fastdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
- java-25-openjdk-static-libs-slowdebug— before 1:25.0.4.0.7-1.1.el10_2.alma.1
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://access.redhat.com/errata/RHSA-2026:42899
- https://bugzilla.redhat.com/2459420
- https://bugzilla.redhat.com/2502751
- https://bugzilla.redhat.com/2502782
- https://bugzilla.redhat.com/2502783
- https://bugzilla.redhat.com/2502784
- https://bugzilla.redhat.com/2502791
- https://bugzilla.redhat.com/2502792
- https://bugzilla.redhat.com/2502793
- https://bugzilla.redhat.com/2503636
- https://errata.almalinux.org/10/ALSA-2026-42899.html
- https://www.redhat.com/security/data/cve/CVE-2026-41254.html
- https://www.redhat.com/security/data/cve/CVE-2026-46917.html
- https://www.redhat.com/security/data/cve/CVE-2026-46968.html
- https://www.redhat.com/security/data/cve/CVE-2026-47010.html
- https://www.redhat.com/security/data/cve/CVE-2026-47021.html
- https://www.redhat.com/security/data/cve/CVE-2026-47027.html
- https://www.redhat.com/security/data/cve/CVE-2026-47059.html
- https://www.redhat.com/security/data/cve/CVE-2026-47063.html
- https://www.redhat.com/security/data/cve/CVE-2026-60147.html
- https://errata.almalinux.org/9/ALSA-2026-42899.html
Structured record: https://osv.dev/vulnerability/ALSA-2026:42899
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta