🛡️ CLSA-2025-1753730595 — java-17-openjdk (CVE-2025-21502 +24 more)
Description
java-17-openjdk: Fix of 25 CVEs
- Update to jdk-17.0.15+6
- Set bundled freetype provide version to 2.13.2
- Set bundled harfbuzz provide version to 8.2.2
- Require tzdata-java 2025a at runtime and for build
- CVE-2025-21502: fix Hotspot component vulnerability allowing unauthorized access
to resources and exposure of sensitive information
- CVE-2025-30698: fix 2D component vulnerability allowing unauthorized data access
and partial denial of service
- CVE-2025-30691: fix Compiler component vulnerability allowing unauthorized data
access and modification (CVSS 4.8 Medium)
- CVE-2025-21587: fix JSSE component vulnerability allowing unauthorized
creation/deletion/modification of critical data
- CVE-2024-20921: fix information disclosure in Hotspot that allows remote attackers
to access sensitive data via untrusted input through exposed APIs or sandboxed
environments
- CVE-2024-21235: fix vulnerability in Hotspot that allows remote attackers to read
or modify limited data via untrusted input through exposed APIs or sandboxed code
- CVE-2024-21217: fix vulnerability in Serialization that allows remote attackers to
trigger partial denial of service via untrusted input through exposed APIs or
sandboxed code
- CVE-2024-21210: fix vulnerability in Hotspot that allows remote attackers to modify
limited data via untrusted input through exposed APIs or sandboxed code.
- CVE-2024-21208: fix security vulnerability in OpenJDK component
- CVE-2024-21147: fix Hotspot component vulnerability allowing unauthorized data access
- CVE-2024-21145: fix 2D component vulnerability allowing unauthorized data access
- CVE-2024-21144: fix security vulnerability in OpenJDK component
- CVE-2024-21140: fix Hotspot component vulnerability
- CVE-2024-21138: fix Hotspot component vulnerability causing partial denial of service
- CVE-2024-21131: fix vulnerability in Hotspot that allows remote attackers to modify
limited data via untrusted input through exposed APIs or sandboxed code
- CVE-2024-21094: fix Hotspot component vulnerability allowing unauthorized data modification
- CVE-2024-21085: fix Concurrency component vulnerability causing partial denial of service
- CVE-2024-21068: fix Hotspot component vulnerability allowing unauthorized data access
- CVE-2024-21011: fix Hotspot component vulnerability causing partial denial of service
- CVE-2024-20918: fix information disclosure and data modification in Hotspot via untrusted input
- CVE-2024-20952: fix information disclosure and data modification in Security via untrusted input
- CVE-2024-20926: fix information disclosure in Scripting via untrusted input
- CVE-2023-48161: fix buffer overflow in GifLib’s DumpSCreen2RGB function allowing local attackers
to access sensitive information
- CVE-2023-22025: fix data modification in Hotspot via untrusted input through exposed
APIs or sandboxed code
- CVE-2023-25193: fix O(n^2) growth vulnerability in HarfBuzz's hb-ot-layout-gsubgpos.hh
when processing consecutive marks
Affected software
CLSA-2025-1753730595 is recorded against 23 packages.
- java-17-openjdk (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-demo (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-demo-fastdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-demo-slowdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-devel (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-devel-fastdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-devel-slowdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-fastdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-headless (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-headless-fastdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-headless-slowdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-javadoc (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-javadoc-zip (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-jmods (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-jmods-fastdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-jmods-slowdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-slowdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-src (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-src-fastdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-src-slowdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-static-libs (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-static-libs-fastdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
- java-17-openjdk-static-libs-slowdebug (fixed in 1:17.0.15.0.6-1.el9.tuxcare.els1)
Timeline and source
Published on 28 July 2025 and last revised on 1 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| java-17-openjdk | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-demo | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-demo-fastdebug | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-demo-slowdebug | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-devel | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-devel-fastdebug | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-devel-slowdebug | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-fastdebug | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-headless | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-headless-fastdebug | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-headless-slowdebug | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-javadoc | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-javadoc-zip | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-jmods | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-jmods-fastdebug | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-jmods-slowdebug | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-slowdebug | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-src | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-src-fastdebug | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-src-slowdebug | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-static-libs | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-static-libs-fastdebug | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
| java-17-openjdk-static-libs-slowdebug | — | 1:17.0.15.0.6-1.el9.tuxcare.els1 |
References
Similar Threats
- Unknown ALSA-2024:8124
- Unknown ALSA-2024:4568
- Unknown ALSA-2024:1825
- Unknown ALSA-2024:0267
- Unknown ALSA-2023:5751
Free Vulnerability Check
Is your site affected by CLSA-2025-1753730595?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CLSA-2025-1753730595 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.