SUSE-SU-2026:3614-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263614-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3614-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:3614-1
Upstream
CVE (14)
Related
Published
2026-08-13T18:02:15Z
Modified
2026-08-14T18:15:06Z
Summary
Security update for java-1_8_0-ibm
Details

This update for java-1_8_0-ibm fixes the following issues:

Update to Java 8.0 Service Refresh 8 Fix Pack 70 (bsc#1273223).

  • CVE-2026-16243: inconsistent handling of zero length data in arraycmp of the SIMD evaluator (bsc#1274275).
  • CVE-2026-16439: using -Xtrace to trace method arguments can lead to buffer underflow (bsc#1272250).
  • CVE-2026-16441: method resolution default method precedence failure (bsc#1272248).
  • CVE-2026-41254: lcms2: information disclosure or denial of service via integer overflow in CubeSize (bsc#1272459).
  • CVE-2026-46968: unauthorized creation, deletion or modification access to critical data (bsc#1272224).
  • CVE-2026-47010: unauthorized update, insert or delete access to data (bsc#1272225).
  • CVE-2026-47021: partial denial of service via multiple network protocols (bsc#1272227).
  • CVE-2026-47027: partial denial of service via multiple network protocols (bsc#1272228).
  • CVE-2026-47057: hang or frequently repeatable crash via multiple network protocols (bsc#1272233).
  • CVE-2026-47058: unauthorized creation, deletion or modification access to critical data (bsc#1272234).
  • CVE-2026-47059: partial denial of service via multiple network protocols (bsc#1272235).
  • CVE-2026-47063: unauthorized creation, deletion or modification access to critical data (bsc#1272236).
  • CVE-2026-60147: unauthorized update, insert or delete access to data (bsc#1272237).
  • CVE-2026-8400: malicious IIOP server can induce loading and instantation of arbitrary classes (bsc#1274276).
References

Affected packages

SUSE:Linux Enterprise Server 12 SP5-LTSS / java-1_8_0-ibm

Package

Name
java-1_8_0-ibm
Purl
pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.8.0_sr8.70-30.153.1

Ecosystem specific

{
    "binaries": [
        {
            "java-1_8_0-ibm": "1.8.0_sr8.70-30.153.1",
            "java-1_8_0-ibm-alsa": "1.8.0_sr8.70-30.153.1",
            "java-1_8_0-ibm-devel": "1.8.0_sr8.70-30.153.1",
            "java-1_8_0-ibm-plugin": "1.8.0_sr8.70-30.153.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3614-1.json"

SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 / java-1_8_0-ibm

Package

Name
java-1_8_0-ibm
Purl
pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.8.0_sr8.70-30.153.1

Ecosystem specific

{
    "binaries": [
        {
            "java-1_8_0-ibm": "1.8.0_sr8.70-30.153.1",
            "java-1_8_0-ibm-alsa": "1.8.0_sr8.70-30.153.1",
            "java-1_8_0-ibm-devel": "1.8.0_sr8.70-30.153.1",
            "java-1_8_0-ibm-plugin": "1.8.0_sr8.70-30.153.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3614-1.json"