🛡️ SUSE-SU-2025:01788-1 — java-1-8-0-ibm (CVE-2025-21587 +3 more)
Description
Security update for java-1_8_0-ibm
This update for java-1_8_0-ibm fixes the following issues:
Update to Java 8.0 Service Refresh 8 Fix Pack 45.
Security issues fixed:
- Oracle April 15 2025 CPU (bsc#1242208)
- CVE-2025-21587: unauthorized access, deletion and modification of critical data via the JSSE component
(bsc#1241274).
- CVE-2025-30691: unauthorized access to data via the Compiler component (bsc#1241275).
- CVE-2025-30698: unauthorized access to data and ability to cause a partial DoS via the 2D component (bsc#1241276).
- IBM Security Update May 2025
- CVE-2025-4447: stack based buffer overflow in Eclipse OpenJ9 through modification of file that is read when the JVM
starts (bsc#1243429).
Other changes and issues fixed:
- Security:
- Avoid memory leak during aes cipher initialization operations
for IBMJCEPlus and IBMJCEPlusProviders provider.
- Changing the default of the com.ibm.security.spnego.msinterop
property from true to false.
- Deserializing a com.ibm.crypto.provider.rsaprivatecrtkey object
causes a java.io.invalidobjectexception to be thrown.
- Failed to read private key from a JKS keystore, specified as
JCEKS keystore.
- HTTPS channel binding support.
- Keytool listing PKCS12 keystore issue.
- On Linux systems, use gcc11.2 to compile IBM PKCS11 library.
- Support has been added to the IBM Java XMLDSigRI security provider
for the EdDSA (Edwards-curve Digital Signature Algorithm).
- Updates to XDH Key Agreement, AESGCM Algorithms in IBMJCEPlus
and IBMJCEPlusFIPS providers.
- Class Libraries:
- Update timezone information to the latest tzdata2025a.
- Java Virtual Machine:
- A SIGSEGV/GPF event received while processing verifyerror.
- Crash while resolving MethodHandleNatives.
- NoSuchMethodException or NoClassDefFoundError when loading classes.
- JIT Compiler:
- Assert in the JIT Compiler, badILOp.
- Reduced MD5 performance.
Affected software
SUSE-SU-2025:01788-1 is recorded against 1 package.
- java-1-8-0-ibm (fixed in 1.8.0_sr8.45-150000.3.101.1)
Timeline and source
Published on 31 May 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| java-1-8-0-ibm | — | 1.8.0_sr8.45-150000.3.101.1 |
References
Similar Threats
- Unknown SUSE-SU-2023:2862-1
- Unknown SUSE-SU-2023:2491-1
- Unknown SUSE-SU-2023:2476-1
- Unknown SUSE-SU-2023:1850-1
- Unknown SUSE-SU-2023:1823-1
Free Vulnerability Check
Is your site affected by SUSE-SU-2025:01788-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:01788-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.