{"id":"USN-7902-1","summary":"openjdk-25-crac vulnerabilities","details":"Jinfeng Guo discovered that the Security component of CRaC JDK 25 did not\ncorrectly handle certain representations of encoded strings. An\nunauthenticated remote attacker could possibly use this issue to modify\nfiles or leak sensitive information. (CVE-2025-53057)\n\nDarius Bohni discovered that the JAXP component of CRaC JDK 25 was\nvulnerable to a XML External Entity (XEE) attack. An unauthenticated\nremote attacker could possibly use this issue to modify files or leak\nsensitive information. (CVE-2025-53066)\n\nYakov Shafranovich discovered that the Libraries component of CRaC JDK\n25 contained an issue where certain Strings built with StringBuilder\nreturned an incorrect result for String.equals() checks. An unauthenticated\nremote attacker could possibly use this issue to update, insert, or\ndelete accessible data. (CVE-2025-61748)\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttps://openjdk.org/groups/vulnerability/advisories/2025-10-21","modified":"2026-04-27T18:29:05.076317Z","published":"2025-12-01T14:48:36Z","related":["UBUNTU-CVE-2025-53057","UBUNTU-CVE-2025-53066","UBUNTU-CVE-2025-61748"],"upstream":["CVE-2025-53057","CVE-2025-53066","CVE-2025-61748","UBUNTU-CVE-2025-53057","UBUNTU-CVE-2025-53066","UBUNTU-CVE-2025-61748"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7902-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-53057"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-53066"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-61748"}],"affected":[{"package":{"name":"openjdk-25-crac","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/openjdk-25-crac@25.0.1+8-0ubuntu1~25.10?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"25.0.1+8-0ubuntu1~25.10"}]}],"versions":["25~26ea-0ubuntu1","25+36-0ubuntu1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"openjdk-25-crac-demo","binary_version":"25.0.1+8-0ubuntu1~25.10"},{"binary_name":"openjdk-25-crac-jdk","binary_version":"25.0.1+8-0ubuntu1~25.10"},{"binary_name":"openjdk-25-crac-jdk-headless","binary_version":"25.0.1+8-0ubuntu1~25.10"},{"binary_name":"openjdk-25-crac-jre","binary_version":"25.0.1+8-0ubuntu1~25.10"},{"binary_name":"openjdk-25-crac-jre-headless","binary_version":"25.0.1+8-0ubuntu1~25.10"},{"binary_name":"openjdk-25-crac-jre-zero","binary_version":"25.0.1+8-0ubuntu1~25.10"},{"binary_name":"openjdk-25-crac-source","binary_version":"25.0.1+8-0ubuntu1~25.10"},{"binary_name":"openjdk-25-crac-testsupport","binary_version":"25.0.1+8-0ubuntu1~25.10"}]},"database_specific":{"cves_map":{"cves":[],"ecosystem":"Ubuntu:25.10"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7902-1.json"}}],"schema_version":"1.7.5"}