Alicja Kario discovered that the JSSE component of CRaC JDK 21 incorrectly handled RSA padding. An Attacker could possibly use this issue to obtain sensitive information. (CVE-2025-21587)
It was discovered that the Compiler component of CRaC JDK 21 incorrectly handled compiler transformations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2025-30691)
It was discovered that the 2D component of CRaC JDK 21 did not properly manage memory under certain circumstances. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2025-30698)
In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes.
Please see the following for more information: https://openjdk.org/groups/vulnerability/advisories/2025-04-15
{ "availability": "No subscription required", "binaries": [ { "binary_version": "21.0.7+6.1-0ubuntu1~25.04", "binary_name": "openjdk-21-crac-demo" }, { "binary_version": "21.0.7+6.1-0ubuntu1~25.04", "binary_name": "openjdk-21-crac-jdk" }, { "binary_version": "21.0.7+6.1-0ubuntu1~25.04", "binary_name": "openjdk-21-crac-jdk-headless" }, { "binary_version": "21.0.7+6.1-0ubuntu1~25.04", "binary_name": "openjdk-21-crac-jre" }, { "binary_version": "21.0.7+6.1-0ubuntu1~25.04", "binary_name": "openjdk-21-crac-jre-headless" }, { "binary_version": "21.0.7+6.1-0ubuntu1~25.04", "binary_name": "openjdk-21-crac-jre-zero" }, { "binary_version": "21.0.7+6.1-0ubuntu1~25.04", "binary_name": "openjdk-21-crac-source" }, { "binary_version": "21.0.7+6.1-0ubuntu1~25.04", "binary_name": "openjdk-21-crac-testsupport" } ] }
{ "ecosystem": "Ubuntu:25.04", "cves": [ { "severity": [ { "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "type": "CVSS_V3" }, { "score": "medium", "type": "Ubuntu" } ], "id": "CVE-2025-21587" }, { "severity": [ { "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N", "type": "CVSS_V3" }, { "score": "medium", "type": "Ubuntu" } ], "id": "CVE-2025-30691" }, { "severity": [ { "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "type": "CVSS_V3" }, { "score": "medium", "type": "Ubuntu" } ], "id": "CVE-2025-30698" } ] }