SUSE SLES12: java-11-openjdk / java-11-openjdk-demo / java-11-openjdk-devel / etc (SUSE-SU-2026:3284-1)

high Nessus Plugin ID 330316

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES12 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3284-1 advisory.

This update for java-11-openjdk fixes the following issues

Upgrade to upstream tag jdk-11.0.32+9 (July 2026 CPU).

Security issues fixed:

- CVE-2026-41254: lcms: information disclosure and denial of service via integer overflow in `CubeSize` (bsc#1264994).
- CVE-2026-46917: unauthenticated attacker with network access via TLS can cause a partial denial of service (bsc#1272223).
- CVE-2026-46968: unauthenticated attacker with network access via TLS can gain unauthorized creation, deletion or modification access to critical data(bsc#1272224).
- CVE-2026-47010: unauthenticated attacker with network access via multiple protocols can gain unauthorized update, insert or delete access to some data (bsc#1272225).
- CVE-2026-47021: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272227).
- CVE-2026-47027: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272228).
- CVE-2026-47057: unauthenticated attacker with network access via multiple protocols can cause a hang or frequently repeatable crash (bsc#1272233).
- CVE-2026-47058: unauthenticated attacker with network access via multiple protocols can gain unauthorized creation, deletion or modification access to critical data (bsc#1272234).
- CVE-2026-47059: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272235).
- CVE-2026-47063: unauthenticated attacker with network access via multiple protocols can gain unauthorized creation, deletion or modification access to critical data (bsc#1272236).
- CVE-2026-60147: unauthenticated attacker with network access via multiple protocols can gain unauthorized update, insert, delete and read access to some(bsc#1272237).

Other updates and bugfixes:

- Errors from update-alternatives when installing java-25-openjdk (bsc#1267355).
- Upgrade to upstream tag jdk-11.0.32+9 (July 2026 CPU):
- JDK-8200566: DistributionPointFetcher fails to fetch CRLs if the DistributionPoints field contains more than one DistributionPoint and the first one fails
- JDK-8242314: use reproducible random in vmTestbase shared code
- JDK-8252412: [macos11] system dynamic libraries removed from filesystem
- JDK-8275405: Linking error for classes with lambda template parameters and virtual functions
- JDK-8275843: Random crashes while the UI code is executed
- JDK-8286562: GCC 12 reports some compiler warnings
- JDK-8287491: compiler/jvmci/errors/TestInvalidDebugInfo.java fails new assert: assert((uint)t < T_CONFLICT + 1) failed:
invalid type #
- JDK-8292177: InitialSecurityProperty JFR event
- JDK-8293691: converting a defined BasicType value to a string should not crash the VM
- JDK-8298730: Refactor subsystem_file_line_contents and add docs and tests
- JDK-8314555: Build with mawk fails on Windows
- JDK-8323672: Suppress unwanted autoconf added flags in CC and CXX
- JDK-8324243: Compilation failures in java.desktop module with gcc 14
- JDK-8325766: Extend CertificateBuilder to create trust and end entity certificates programmatically
- JDK-8327071: [Testbug] g-tests for cgroup leave files in /tmp on linux
- JDK-8336498: [macos] [build]: install-file macro may run into permission denied error
- JDK-8342858: Make target mac-jdk-bundle fails on chmod command
- JDK-8347740: java/io/File/createTempFile/SpecialTempFile.java failing
- JDK-8347811: Container detection code for cgroups v2 should use cgroup.controllers
- JDK-8349988: Change cgroup version detection logic to not depend on /proc/cgroups
- JDK-8350749: Upgrade JLine to 3.29.0
- JDK-8351359: OperatingSystemMXBean: values from getCpuLoad and getProcessCpuLoad are stale after 24.8 days (Windows)
- JDK-8353714: [17u] Backport of 8347740 incomplete
- JDK-8354878: File Leak in CgroupSubsystemFactory::determine_type of cgroupSubsystem_linux.cpp:300 + JDK-8355077: Compiler error at splashscreen_gif.c due to unterminated string initialization + JDK-8363966: GHA: Switch cross-compiling sysroots to Debian trixie + JDK-8365098: make/RunTests.gmk generates a wrong path to test artifacts on Alpine + JDK-8365660: test/jdk/sun/security/pkcs11/KeyAgreement/ tests skipped without SkipExceprion + JDK-8366159: SkippedException is treated as a pass for pkcs11/KeyStore, pkcs11/SecretKeyFactory and pkcs11/SecureRandom + JDK-8367766: [11u] src/jdk.crypto.ec/share/native/libsunec/ /impl/mpi.c:321:3: error: 'tmp.dp' may be used uninitialized + JDK-8368041: Enhance TLS certificate handling + JDK-8368670: Deadlock in JFR on event register + class load + JDK-8369032: Add test to ensure serialized ICC_Profile stores only necessary optional data + JDK-8369506: Bytecode rewriting causes Java heap corruption on AArch64 + JDK-8371559: Intermittent timeouts in test javax/net/ssl/Stapling/HttpsUrlConnClient.java + JDK-8372351: Add 2 WISeKey roots + JDK-8373275: Improve DTLS handshaking + JDK-8374058: Enhance JPEG handling + JDK-8374888: Implement internal test cache to help UserIterCount test performance + JDK-8375065: Update LCMS to 2.18 + JDK-8377158: Enhance XBM image support + JDK-8377167: javax/imageio/ReadAbortTest.java throw NPE when x11 unavailable + JDK-8377498: Improve HttpServer handling + JDK-8377833: Enhance Jar file processing + JDK-8378218: MSYS2 reports cygwin triplet causing bash configure failure + JDK-8378631: Update Zlib Data Compression Library to Version 1.3.2 + JDK-8378687: Improve delegation of HttpURLConnection + JDK-8378823: AIX build fails after zlib updated by JDK-8378631 + JDK-8379685: Bump update version of OpenJDK: 11.0.32 + JDK-8380672: Improve certification checking + JDK-8380947: Add pull request template + JDK-8381039: Enhance AWT ImagingLib + JDK-8381049: Enhance Jar handling + JDK-8381185: Improve Nashorn index handling + JDK-8381195: Enhance Dataview Implementation + JDK-8381519: Enhance Der Value Handling + JDK-8381551: DisabledCurve test fails on Windows after disabling SHA1 + JDK-8381796: Enhance Certificate parsing + JDK-8383175: (tz) Update Timezone Data to 2026b + JDK-8383354: Update LCMS to 2.19.1 + JDK-8383473: Follow on from tzdata2026b time change to include temporary hack BC time change + JDK-8384158: GHA: Downgrade Windows GHA runners to windows-2022 temporarily + JDK-8384495: Update Libpng to 1.6.58 + JDK-8384902: Update GIFlib to 6.1.3 + JDK-8386551: Windows build broken because of MSys2/Make update + JDK-8387976: [11u] Remove designator DEFAULT_PROMOTED_VERSION_PRE=ea for release 11.0.32
- Make post scripts less noisy (bsc#1267355).
- Use libalternatives instead of update-alternatives for distributions where libalternatives is available.

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected java-11-openjdk, java-11-openjdk-demo, java-11-openjdk-devel and / or java-11-openjdk-headless packages.

See Also

https://bugzilla.suse.com/1264994

https://bugzilla.suse.com/1267355

https://bugzilla.suse.com/1272223

https://bugzilla.suse.com/1272224

https://bugzilla.suse.com/1272225

https://bugzilla.suse.com/1272227

https://bugzilla.suse.com/1272228

https://bugzilla.suse.com/1272233

https://bugzilla.suse.com/1272234

https://bugzilla.suse.com/1272235

https://bugzilla.suse.com/1272236

https://bugzilla.suse.com/1272237

https://www.suse.com/security/cve/CVE-2026-41254

https://www.suse.com/security/cve/CVE-2026-46917

https://www.suse.com/security/cve/CVE-2026-46968

https://www.suse.com/security/cve/CVE-2026-47010

https://www.suse.com/security/cve/CVE-2026-47021

https://www.suse.com/security/cve/CVE-2026-47027

https://www.suse.com/security/cve/CVE-2026-47057

https://www.suse.com/security/cve/CVE-2026-47058

https://www.suse.com/security/cve/CVE-2026-47059

https://www.suse.com/security/cve/CVE-2026-47063

https://www.suse.com/security/cve/CVE-2026-60147

http://www.nessus.org/u?1ee286b5

Plugin Details

Severity: High

ID: 330316

File Name: suse_SU-2026-3284-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 7/28/2026

Updated: 7/28/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.64

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-41254

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:12, p-cpe:/a:novell:suse_linux:java-11-openjdk-demo, p-cpe:/a:novell:suse_linux:java-11-openjdk-devel, p-cpe:/a:novell:suse_linux:java-11-openjdk-headless, p-cpe:/a:novell:suse_linux:java-11-openjdk

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/27/2026

Vulnerability Publication Date: 4/18/2026

Reference Information

CVE: CVE-2026-41254, CVE-2026-46917, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47057, CVE-2026-47058, CVE-2026-47059, CVE-2026-47063, CVE-2026-60147

SuSE: SUSE-SU-2026:3284-1