CVE-2026-22007

high
Published 2026-04-24 Β· Modified 2026-06-01
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
8.0

Description

RHSA-2026:22139: java-1.8.0-ibm security update (Important)

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description openjdk: Enhance crypto algorithm support (Oracle CPU 2026-04) CVSS v3: 2.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N) Errata / fixed releases ProductPackageAdvisoryReleased OPENJDK ELS 11.0.31java-11-openjdk-portableRHSA-2026:92552026-04-22T00:00:00Z OPENJDK ELS 11.0.31java-11-openjdk-windowsRHSA-2026:92562026-04-22T00:00:00Z Red Hat Build of OpenJDK…

Description

openjdk: Enhance crypto algorithm support (Oracle CPU 2026-04)

CVSS v3: 2.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
OPENJDK ELS 11.0.31java-11-openjdk-portableRHSA-2026:92552026-04-22T00:00:00Z
OPENJDK ELS 11.0.31java-11-openjdk-windowsRHSA-2026:92562026-04-22T00:00:00Z
Red Hat Build of OpenJDK 17.0.19java-17-openjdk-windowsRHSA-2026:96882026-04-23T00:00:00Z
Red Hat Build of OpenJDK 17.0.9java-17-openjdk-portableRHSA-2026:96872026-04-23T00:00:00Z
Red Hat Build of OpenJDK 21.0.11java-21-openjdk-portableRHSA-2026:96902026-04-23T00:00:00Z
Red Hat Build of OpenJDK 21.0.11java-21-openjdk-windowsRHSA-2026:96912026-04-23T00:00:00Z
Red Hat Build of OpenJDK 25.0.3java-25-openjdk-portableRHSA-2026:96942026-04-23T00:00:00Z
Red Hat Build of OpenJDK 8u492java-1.8.0-openjdk-portableRHSA-2026:96842026-04-23T00:00:00Z
Red Hat Build of OpenJDK 8u492java-1.8.0-openjdk-windowsRHSA-2026:96852026-04-23T00:00:00Z
Red Hat Enterprise Linux 10java-21-openjdk-1:21.0.11.0.10-2.el10_2RHSA-2026:96892026-04-24T00:00:00Z
Red Hat Enterprise Linux 10java-25-openjdk-1:25.0.3.0.9-1.el10_2RHSA-2026:96932026-04-22T00:00:00Z
Red Hat Enterprise Linux 10.0 Extended Update Supportjava-21-openjdk-1:21.0.11.0.10-1.el10_2RHSA-2026:96892026-04-24T00:00:00Z
Red Hat Enterprise Linux 7 Extended Lifecycle Supportjava-1.8.0-openjdk-1:1.8.0.492.b09-1.el7_9RHSA-2026:96822026-04-22T00:00:00Z
Red Hat Enterprise Linux 8java-1.8.0-openjdk-1:1.8.0.492.b09-1.el8RHSA-2026:96832026-04-24T00:00:00Z
Red Hat Enterprise Linux 8java-17-openjdk-1:17.0.19.0.10-1.el8RHSA-2026:96862026-04-24T00:00:00Z
Red Hat Enterprise Linux 8java-21-openjdk-1:21.0.11.0.10-1.el8RHSA-2026:96892026-04-24T00:00:00Z
Red Hat Enterprise Linux 8.2 Advanced Update Supportjava-1.8.0-openjdk-1:1.8.0.492.b09-1.el8RHSA-2026:96832026-04-24T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportjava-1.8.0-openjdk-1:1.8.0.492.b09-1.el8RHSA-2026:96832026-04-24T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportjava-17-openjdk-1:17.0.19.0.10-1.el8RHSA-2026:96862026-04-24T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onjava-1.8.0-openjdk-1:1.8.0.492.b09-1.el8RHSA-2026:96832026-04-24T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onjava-17-openjdk-1:17.0.19.0.10-1.el8RHSA-2026:96862026-04-24T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportjava-1.8.0-openjdk-1:1.8.0.492.b09-1.el8RHSA-2026:96832026-04-24T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportjava-17-openjdk-1:17.0.19.0.10-1.el8RHSA-2026:96862026-04-24T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicejava-1.8.0-openjdk-1:1.8.0.492.b09-1.el8RHSA-2026:96832026-04-24T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicejava-17-openjdk-1:17.0.19.0.10-1.el8RHSA-2026:96862026-04-24T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsjava-1.8.0-openjdk-1:1.8.0.492.b09-1.el8RHSA-2026:96832026-04-24T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsjava-17-openjdk-1:17.0.19.0.10-1.el8RHSA-2026:96862026-04-24T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Servicejava-1.8.0-openjdk-1:1.8.0.492.b09-1.el8RHSA-2026:96832026-04-24T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Servicejava-17-openjdk-1:17.0.19.0.10-1.el8RHSA-2026:96862026-04-24T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionsjava-1.8.0-openjdk-1:1.8.0.492.b09-1.el8RHSA-2026:96832026-04-24T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionsjava-17-openjdk-1:17.0.19.0.10-1.el8RHSA-2026:96862026-04-24T00:00:00Z
Red Hat Enterprise Linux 9java-1.8.0-openjdk-1:1.8.0.492.b09-2.el9RHSA-2026:96832026-04-24T00:00:00Z
Red Hat Enterprise Linux 9java-17-openjdk-1:17.0.19.0.10-2.el9RHSA-2026:96862026-04-24T00:00:00Z
Red Hat Enterprise Linux 9java-21-openjdk-1:21.0.11.0.10-2.el9RHSA-2026:96892026-04-24T00:00:00Z
Red Hat Enterprise Linux 9java-25-openjdk-1:25.0.3.0.9-1.el9RHSA-2026:96932026-04-22T00:00:00Z
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionsjava-1.8.0-openjdk-1:1.8.0.492.b09-1.el9RHSA-2026:96832026-04-24T00:00:00Z
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionsjava-17-openjdk-1:17.0.19.0.10-1.el9RHSA-2026:96862026-04-24T00:00:00Z
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionsjava-1.8.0-openjdk-1:1.8.0.492.b09-1.el9RHSA-2026:96832026-04-24T00:00:00Z
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionsjava-17-openjdk-1:17.0.19.0.10-1.el9RHSA-2026:96862026-04-24T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportjava-1.8.0-openjdk-1:1.8.0.492.b09-1.el9RHSA-2026:96832026-04-24T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportjava-17-openjdk-1:17.0.19.0.10-1.el9RHSA-2026:96862026-04-24T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportjava-21-openjdk-1:21.0.11.0.10-1.el9RHSA-2026:96892026-04-24T00:00:00Z
Red Hat Enterprise Linux 9.6 Extended Update Supportjava-1.8.0-openjdk-1:1.8.0.492.b09-1.el9RHSA-2026:96832026-04-24T00:00:00Z
Red Hat Enterprise Linux 9.6 Extended Update Supportjava-17-openjdk-1:17.0.19.0.10-1.el9RHSA-2026:96862026-04-24T00:00:00Z
Red Hat Enterprise Linux 9.6 Extended Update Supportjava-21-openjdk-1:21.0.11.0.10-1.el9RHSA-2026:96892026-04-24T00:00:00Z
Red Hat OpenJDK 11 els for RHEL 7java-11-openjdk-1:11.0.31.0.11-1.el7_9RHSA-2026:92542026-04-22T00:00:00Z
Red Hat OpenJDK 11 els for RHEL 8java-11-openjdk-1:11.0.31.0.11-1.el8RHSA-2026:92542026-04-22T00:00:00Z
Red Hat OpenJDK 11 els for RHEL 9java-11-openjdk-1:11.0.31.0.11-1.el9RHSA-2026:92542026-04-22T00:00:00Z
Temurin Build of OpenJDK 25.0.3java-25-openjdk-windowsRHSA-2026:118222026-04-30T00:00:00Z
Red Hat Hardened Imagesjava-21-openjdk-portable-main-21.0.11.0.10-2.hum1RHSA-2026:114032026-04-28T00:00:00Z
Red Hat Hardened Imagesjava-21-openjdk-main-21.0.11.0.10-1.hum1RHSA-2026:116552026-04-29T00:00:00Z
Red Hat Hardened Imagesjava-25-openjdk-portable-main-25.0.3.0.9-1.hum1RHSA-2026:118292026-04-29T00:00:00Z
Red Hat Hardened Imagesjava-25-openjdk-main-25.0.3.0.9-1.hum1RHSA-2026:119022026-04-29T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 10java-21-ibm-semeru-certified-jdkAffected
Red Hat Enterprise Linux 6java-1.6.0-openjdkOut of support scope
Red Hat Enterprise Linux 6java-1.7.0-openjdkOut of support scope
Red Hat Enterprise Linux 6java-1.8.0-openjdkOut of support scope
Red Hat Enterprise Linux 7java-1.6.0-openjdkOut of support scope
Red Hat Enterprise Linux 7java-1.7.0-openjdkOut of support scope
Red Hat Enterprise Linux 8java-1.8.0-ibmAffected

Apply commands

bash fix
Apply RHSA-2026:9255 for OPENJDK ELS 11.0.31
yum update -y java
# or:
dnf upgrade -y java

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 8Affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed java-1.8.0-openjdk-demo-1.8.0.492.b09-2.el9.alma.1.aarch64.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 21.0.11+10-1~deb13u2
sid Fixed 11.0.31+11-1
forky Fixed 21.0.11+10-1
bullseye Fixed 11.0.31+11-1~deb11u1
bookworm Fixed 17.0.19+10-1~deb12u2
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
9 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.