🛡️ SUSE-SU-2025:02657-1 — java-21-openjdk (CVE-2025-30749 +3 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for java-21-openjdk

This update for java-21-openjdk fixes the following issues:

Update to upstream tag jdk-21.0.8+9 (July 2025 CPU):

Security fixes:

  • CVE-2025-30749: several scenarios can lead to heap corruption (bsc#1246595)
  • CVE-2025-30754: incomplete handshake may lead to weakening TLS protections (bsc#1246598)
  • CVE-2025-50059: Improve HTTP client header handling (bsc#1246575)
  • CVE-2025-50106: Glyph out-of-memory access and crash (bsc#1246584)

Other fixes:

  • Allow compilation of openjdk for 40 years (bsc#1213796)

Changelog:

+ JDK-6956385: URLConnection.getLastModified() leaks file

handles for jar:file and file: URLs

+ JDK-8051591: Test

javax/swing/JTabbedPane/8007563/Test8007563.java fails

+ JDK-8136895: Writer not closed with disk full error, file

resource leaked

+ JDK-8180450: secondary_super_cache does not scale well

+ JDK-8183348: Better cleanup for

jdk/test/sun/security/pkcs12/P12SecretKey.java

+ JDK-8200566: DistributionPointFetcher fails to fetch CRLs if

the DistributionPoints field contains more than one

DistributionPoint and the first one fails

+ JDK-8202100: Merge vm/share/InMemoryJavaCompiler w/

jdk/test/lib/compiler/InMemoryJavaCompiler

+ JDK-8210471: GZIPInputStream constructor could leak an

un-end()ed Inflater

+ JDK-8211400: nsk.share.gc.Memory::getArrayLength returns

wrong value

+ JDK-8220213: com/sun/jndi/dns/ConfigTests/Timeout.java

failed intermittent

+ JDK-8249831: Test sun/security/mscapi/nonUniqueAliases/

/NonUniqueAliases.java is marked with @ignore

+ JDK-8253440: serviceability/sa/TestJhsdbJstackLineNumbers.java

failed with 'Didn't find enough line numbers'

+ JDK-8256211: assert fired in

java/net/httpclient/DependentPromiseActionsTest (infrequent)

+ JDK-8258483: [TESTBUG] gtest

CollectorPolicy.young_scaled_initial_ergo_vm fails if heap is

too small

+ JDK-8267174: Many test files have the wrong Copyright header

+ JDK-8270269: Desktop.browse method fails if earlier

CoInitialize call as COINIT_MULTITHREADED

+ JDK-8276995: Bug in jdk.jfr.event.gc.collection.TestSystemGC

+ JDK-8279016: JFR Leak Profiler is broken with Shenandoah

+ JDK-8280991: [XWayland] No displayChanged event after

setDisplayMode call

+ JDK-8281511: java/net/ipv6tests/UdpTest.java fails with

checkTime failed

+ JDK-8282726: java/net/vthread/BlockingSocketOps.java

timeout/hang intermittently on Windows

+ JDK-8286204: [Accessibility,macOS,VoiceOver] VoiceOver reads

the spinner value 10 as 1 when user iterates to 10 for the

first time on macOS

+ JDK-8286789: Test forceEarlyReturn002.java timed out

+ JDK-8286875: ProgrammableUpcallHandler::on_entry/on_exit

access thread fields from native

+ JDK-8294155: Exception thrown before awaitAndCheck hangs

PassFailJFrame

+ JDK-8295804: javax/swing/JFileChooser/

/JFileChooserSetLocationTest.java failed with 'setLocation()

is not working properly'

+ JDK-8297692: Avoid sending per-region GCPhaseParallel JFR

events in G1ScanCollectionSetRegionClosure

+ JDK-8303770: Remove Baltimore root certificate expiring in

May 2025

+ JDK-8305010: Test vmTestbase/nsk/jvmti/scenarios/sampling/

/SP05/sp05t003/TestDescription.java timed out: thread not

suspended

+ JDK-8307318: Test serviceability/sa/

/ClhsdbCDSJstackPrintAll.java failed:

ArrayIndexOutOfBoundsException

+ JDK-8307824: Clean up Finalizable.java and finalize

terminology in vmTestbase/nsk/share

+ JDK-8308033: The jcmd thread dump related tests should test

virtual threads

+ JDK-8308966: Add intrinsic for float/double modulo for x86

AVX2 and AVX512

+ JDK-8309667: TLS handshake fails because of

ConcurrentModificationException in PKCS12KeyStore

.engineGetEntry

+ JDK-8309841: Jarsigner should print a warning if an entry is

removed

+ JDK-8309978: [x64] Fix useless padding

+ JDK-8310066: Improve test coverage for JVMTI GetThreadState

on carrier and mounted vthread

+ JDK-8310525: DynamicLauncher for JDP test needs to try

harder to find a free port

+ JDK-8310643: Misformatted copyright messages in FFM

+ JDK-8312246: NPE when HSDB visits bad oop

+ JDK-8312475: org.jline.util.PumpReader signed byte problem

+ JDK-8313290: Misleading exception message from

STS.Subtask::get when task forked after shutdown

+ JDK-8313430: [JVMCI] fatal error: Never compilable: in JVMCI

shutdown

+ JDK-8313654: Test WaitNotifySuspendedVThreadTest.java timed

out

+ JDK-8314056: Remove runtime platform check from frem/drem

+ JDK-8314136: Test java/net/httpclient/CancelRequestTest.java

failed: WARNING: tracker for HttpClientImpl(42) has

outstanding operations

+ JDK-8314236: Overflow in Collections.rotate

Affected software

SUSE-SU-2025:02657-1 is recorded against 1 package.

  • java-21-openjdk (fixed in 21.0.8.0-150600.3.15.1)

Timeline and source

Published on 4 August 2025 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-08-04
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
java-21-openjdk 21.0.8.0-150600.3.15.1

Similar Threats

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:02657-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:02657-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2025