🛡️ CLSA-2025-1753730595 — java-17-openjdk (CVE-2025-21502 +24 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

java-17-openjdk: Fix of 25 CVEs

  • Update to jdk-17.0.15+6
  • Set bundled freetype provide version to 2.13.2
  • Set bundled harfbuzz provide version to 8.2.2
  • Require tzdata-java 2025a at runtime and for build
  • CVE-2025-21502: fix Hotspot component vulnerability allowing unauthorized access

to resources and exposure of sensitive information

  • CVE-2025-30698: fix 2D component vulnerability allowing unauthorized data access

and partial denial of service

  • CVE-2025-30691: fix Compiler component vulnerability allowing unauthorized data

access and modification (CVSS 4.8 Medium)

  • CVE-2025-21587: fix JSSE component vulnerability allowing unauthorized

creation/deletion/modification of critical data

  • CVE-2024-20921: fix information disclosure in Hotspot that allows remote attackers

to access sensitive data via untrusted input through exposed APIs or sandboxed

environments

  • CVE-2024-21235: fix vulnerability in Hotspot that allows remote attackers to read

or modify limited data via untrusted input through exposed APIs or sandboxed code

  • CVE-2024-21217: fix vulnerability in Serialization that allows remote attackers to

trigger partial denial of service via untrusted input through exposed APIs or

sandboxed code

  • CVE-2024-21210: fix vulnerability in Hotspot that allows remote attackers to modify

limited data via untrusted input through exposed APIs or sandboxed code.

  • CVE-2024-21208: fix security vulnerability in OpenJDK component
  • CVE-2024-21147: fix Hotspot component vulnerability allowing unauthorized data access
  • CVE-2024-21145: fix 2D component vulnerability allowing unauthorized data access
  • CVE-2024-21144: fix security vulnerability in OpenJDK component
  • CVE-2024-21140: fix Hotspot component vulnerability
  • CVE-2024-21138: fix Hotspot component vulnerability causing partial denial of service
  • CVE-2024-21131: fix vulnerability in Hotspot that allows remote attackers to modify

limited data via untrusted input through exposed APIs or sandboxed code

  • CVE-2024-21094: fix Hotspot component vulnerability allowing unauthorized data modification
  • CVE-2024-21085: fix Concurrency component vulnerability causing partial denial of service
  • CVE-2024-21068: fix Hotspot component vulnerability allowing unauthorized data access
  • CVE-2024-21011: fix Hotspot component vulnerability causing partial denial of service
  • CVE-2024-20918: fix information disclosure and data modification in Hotspot via untrusted input
  • CVE-2024-20952: fix information disclosure and data modification in Security via untrusted input
  • CVE-2024-20926: fix information disclosure in Scripting via untrusted input
  • CVE-2023-48161: fix buffer overflow in GifLib’s DumpSCreen2RGB function allowing local attackers

to access sensitive information

  • CVE-2023-22025: fix data modification in Hotspot via untrusted input through exposed

APIs or sandboxed code

  • CVE-2023-25193: fix O(n^2) growth vulnerability in HarfBuzz's hb-ot-layout-gsubgpos.hh

when processing consecutive marks

Affected software

CLSA-2025-1753730595 is recorded against 23 packages.

  • java-17-openjdk (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-demo (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-demo-fastdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-demo-slowdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-devel (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-devel-fastdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-devel-slowdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-fastdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-headless (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-headless-fastdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-headless-slowdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-javadoc (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-javadoc-zip (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-jmods (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-jmods-fastdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-jmods-slowdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-slowdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-src (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-src-fastdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-src-slowdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-static-libs (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-static-libs-fastdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
  • java-17-openjdk-static-libs-slowdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)

Timeline and source

Published on 28 July 2025 and last revised on 1 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

errata.tuxcare.com (Advisory)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-07-28
Updated 2026-08-20
Modified 2026-06-01
Fix URL N/A

Affected Packages

Software From version Fixed in
java-17-openjdk 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-demo 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-demo-fastdebug 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-demo-slowdebug 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-devel 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-devel-fastdebug 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-devel-slowdebug 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-fastdebug 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-headless 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-headless-fastdebug 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-headless-slowdebug 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-javadoc 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-javadoc-zip 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-jmods 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-jmods-fastdebug 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-jmods-slowdebug 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-slowdebug 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-src 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-src-fastdebug 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-src-slowdebug 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-static-libs 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-static-libs-fastdebug 1:17.0.15.0.6-1.el9.tuxcare.els1
java-17-openjdk-static-libs-slowdebug 1:17.0.15.0.6-1.el9.tuxcare.els1

Similar Threats

Free Vulnerability Check

Is your site affected by CLSA-2025-1753730595?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CLSA-2025-1753730595 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesChainguardChainguard 2025