{"id":"RHSA-2026:42876","summary":"Red Hat Security Advisory: java-1.8.0-openjdk security update","modified":"2026-07-28T10:13:00Z","published":"2026-07-24T10:10:21Z","upstream":["CVE-2026-41254","CVE-2026-46968","CVE-2026-47010","CVE-2026-47021","CVE-2026-47027","CVE-2026-47057","CVE-2026-47058","CVE-2026-47059","CVE-2026-47063","CVE-2026-60147"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42876"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2459420"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502751"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502783"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502784"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502791"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502792"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502793"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502794"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502795"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2503636"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_42876.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-41254"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-41254"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41254"},{"type":"ARTICLE","url":"https://abhinavagarwal07.github.io/posts/lcms2-cubesize-overflow/"},{"type":"ARTICLE","url":"https://github.com/mm2/Little-CMS/commit/da6110b1d14abc394633a388209abd5ebedd7ab0"},{"type":"ARTICLE","url":"https://github.com/mm2/Little-CMS/commit/e0641b1828d0a1af5ecb1b11fe22f24fceefd4bc"},{"type":"ARTICLE","url":"https://github.com/mm2/Little-CMS/security/advisories/GHSA-4xp6-rcgg-m9qq"},{"type":"ARTICLE","url":"https://www.openwall.com/lists/oss-security/2026/04/17/16"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-46968"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-46968"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46968"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-47010"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-47010"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47010"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-47021"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-47021"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47021"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-47027"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-47027"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47027"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-47057"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-47057"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47057"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-47058"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-47058"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47058"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-47059"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-47059"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47059"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-47063"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-47063"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47063"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-60147"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-60147"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-60147"}],"affected":[{"package":{"name":"java-1.8.0-openjdk","ecosystem":"Red Hat:rhel_els:7","purl":"pkg:rpm/redhat/java-1.8.0-openjdk"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.502.b07-1.1.el7_9"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:42876.json"}},{"package":{"name":"java-1.8.0-openjdk-debuginfo","ecosystem":"Red Hat:rhel_els:7","purl":"pkg:rpm/redhat/java-1.8.0-openjdk-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.502.b07-1.1.el7_9"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:42876.json"}},{"package":{"name":"java-1.8.0-openjdk-devel","ecosystem":"Red Hat:rhel_els:7","purl":"pkg:rpm/redhat/java-1.8.0-openjdk-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.502.b07-1.1.el7_9"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:42876.json"}},{"package":{"name":"java-1.8.0-openjdk-headless","ecosystem":"Red Hat:rhel_els:7","purl":"pkg:rpm/redhat/java-1.8.0-openjdk-headless"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.502.b07-1.1.el7_9"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:42876.json"}},{"package":{"name":"java-1.8.0-openjdk-accessibility","ecosystem":"Red Hat:rhel_els:7","purl":"pkg:rpm/redhat/java-1.8.0-openjdk-accessibility"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.502.b07-1.1.el7_9"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:42876.json"}},{"package":{"name":"java-1.8.0-openjdk-demo","ecosystem":"Red Hat:rhel_els:7","purl":"pkg:rpm/redhat/java-1.8.0-openjdk-demo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.502.b07-1.1.el7_9"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:42876.json"}},{"package":{"name":"java-1.8.0-openjdk-javadoc","ecosystem":"Red Hat:rhel_els:7","purl":"pkg:rpm/redhat/java-1.8.0-openjdk-javadoc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.502.b07-1.1.el7_9"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:42876.json"}},{"package":{"name":"java-1.8.0-openjdk-javadoc-zip","ecosystem":"Red Hat:rhel_els:7","purl":"pkg:rpm/redhat/java-1.8.0-openjdk-javadoc-zip"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.502.b07-1.1.el7_9"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:42876.json"}},{"package":{"name":"java-1.8.0-openjdk-src","ecosystem":"Red Hat:rhel_els:7","purl":"pkg:rpm/redhat/java-1.8.0-openjdk-src"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.502.b07-1.1.el7_9"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:42876.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}