Alicja Kario discovered that the JSSE component of OpenJDK 8 incorrectly handled RSA padding. An Attacker could possibly use this issue to obtain sensitive information. (CVE-2025-21587)
It was discovered that the Compiler component of OpenJDK 8 incorrectly handled compiler transformations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2025-30691)
It was discovered that the 2D component of OpenJDK 8 did not properly manage memory under certain circumstances. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2025-30698)
In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes.
Please see the following for more information: https://openjdk.org/groups/vulnerability/advisories/2025-04-15
{ "availability": "No subscription required", "binaries": [ { "binary_version": "8u452-ga~us1-0ubuntu1~20.04", "binary_name": "openjdk-8-demo" }, { "binary_version": "8u452-ga~us1-0ubuntu1~20.04", "binary_name": "openjdk-8-jdk" }, { "binary_version": "8u452-ga~us1-0ubuntu1~20.04", "binary_name": "openjdk-8-jdk-headless" }, { "binary_version": "8u452-ga~us1-0ubuntu1~20.04", "binary_name": "openjdk-8-jre" }, { "binary_version": "8u452-ga~us1-0ubuntu1~20.04", "binary_name": "openjdk-8-jre-headless" }, { "binary_version": "8u452-ga~us1-0ubuntu1~20.04", "binary_name": "openjdk-8-jre-zero" }, { "binary_version": "8u452-ga~us1-0ubuntu1~20.04", "binary_name": "openjdk-8-source" } ] }
{ "ecosystem": "Ubuntu:20.04:LTS", "cves": [ { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-21587" }, { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-30691" }, { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-30698" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "8u452-ga~us1-0ubuntu1~22.04", "binary_name": "openjdk-8-demo" }, { "binary_version": "8u452-ga~us1-0ubuntu1~22.04", "binary_name": "openjdk-8-jdk" }, { "binary_version": "8u452-ga~us1-0ubuntu1~22.04", "binary_name": "openjdk-8-jdk-headless" }, { "binary_version": "8u452-ga~us1-0ubuntu1~22.04", "binary_name": "openjdk-8-jre" }, { "binary_version": "8u452-ga~us1-0ubuntu1~22.04", "binary_name": "openjdk-8-jre-headless" }, { "binary_version": "8u452-ga~us1-0ubuntu1~22.04", "binary_name": "openjdk-8-jre-zero" }, { "binary_version": "8u452-ga~us1-0ubuntu1~22.04", "binary_name": "openjdk-8-source" } ] }
{ "ecosystem": "Ubuntu:22.04:LTS", "cves": [ { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-21587" }, { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-30691" }, { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-30698" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "8u452-ga~us1-0ubuntu1~24.04", "binary_name": "openjdk-8-demo" }, { "binary_version": "8u452-ga~us1-0ubuntu1~24.04", "binary_name": "openjdk-8-jdk" }, { "binary_version": "8u452-ga~us1-0ubuntu1~24.04", "binary_name": "openjdk-8-jdk-headless" }, { "binary_version": "8u452-ga~us1-0ubuntu1~24.04", "binary_name": "openjdk-8-jre" }, { "binary_version": "8u452-ga~us1-0ubuntu1~24.04", "binary_name": "openjdk-8-jre-headless" }, { "binary_version": "8u452-ga~us1-0ubuntu1~24.04", "binary_name": "openjdk-8-jre-zero" }, { "binary_version": "8u452-ga~us1-0ubuntu1~24.04", "binary_name": "openjdk-8-source" } ] }
{ "ecosystem": "Ubuntu:24.04:LTS", "cves": [ { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-21587" }, { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-30691" }, { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-30698" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "8u452-ga~us1-0ubuntu1~25.04", "binary_name": "openjdk-8-demo" }, { "binary_version": "8u452-ga~us1-0ubuntu1~25.04", "binary_name": "openjdk-8-jdk" }, { "binary_version": "8u452-ga~us1-0ubuntu1~25.04", "binary_name": "openjdk-8-jdk-headless" }, { "binary_version": "8u452-ga~us1-0ubuntu1~25.04", "binary_name": "openjdk-8-jre" }, { "binary_version": "8u452-ga~us1-0ubuntu1~25.04", "binary_name": "openjdk-8-jre-headless" }, { "binary_version": "8u452-ga~us1-0ubuntu1~25.04", "binary_name": "openjdk-8-jre-zero" }, { "binary_version": "8u452-ga~us1-0ubuntu1~25.04", "binary_name": "openjdk-8-source" } ] }
{ "ecosystem": "Ubuntu:25.04", "cves": [ { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-21587" }, { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-30691" }, { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-30698" } ] }
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "binaries": [ { "binary_version": "8u452-ga~us1-0ubuntu1~16.04.1", "binary_name": "openjdk-8-demo" }, { "binary_version": "8u452-ga~us1-0ubuntu1~16.04.1", "binary_name": "openjdk-8-jdk" }, { "binary_version": "8u452-ga~us1-0ubuntu1~16.04.1", "binary_name": "openjdk-8-jdk-headless" }, { "binary_version": "8u452-ga~us1-0ubuntu1~16.04.1", "binary_name": "openjdk-8-jre" }, { "binary_version": "8u452-ga~us1-0ubuntu1~16.04.1", "binary_name": "openjdk-8-jre-headless" }, { "binary_version": "8u452-ga~us1-0ubuntu1~16.04.1", "binary_name": "openjdk-8-jre-jamvm" }, { "binary_version": "8u452-ga~us1-0ubuntu1~16.04.1", "binary_name": "openjdk-8-jre-zero" }, { "binary_version": "8u452-ga~us1-0ubuntu1~16.04.1", "binary_name": "openjdk-8-source" } ] }
{ "ecosystem": "Ubuntu:Pro:16.04:LTS", "cves": [ { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-21587" }, { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-30691" }, { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-30698" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_version": "8u452-ga~us1-0ubuntu1~18.04", "binary_name": "openjdk-8-demo" }, { "binary_version": "8u452-ga~us1-0ubuntu1~18.04", "binary_name": "openjdk-8-jdk" }, { "binary_version": "8u452-ga~us1-0ubuntu1~18.04", "binary_name": "openjdk-8-jdk-headless" }, { "binary_version": "8u452-ga~us1-0ubuntu1~18.04", "binary_name": "openjdk-8-jre" }, { "binary_version": "8u452-ga~us1-0ubuntu1~18.04", "binary_name": "openjdk-8-jre-headless" }, { "binary_version": "8u452-ga~us1-0ubuntu1~18.04", "binary_name": "openjdk-8-jre-zero" }, { "binary_version": "8u452-ga~us1-0ubuntu1~18.04", "binary_name": "openjdk-8-source" } ] }
{ "ecosystem": "Ubuntu:Pro:18.04:LTS", "cves": [ { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-21587" }, { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-30691" }, { "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" }, { "type": "Ubuntu", "score": "medium" } ], "id": "CVE-2025-30698" } ] }