RHSA-2026:55774: Moderate: java-1.8.0-openjdk security update
Moderate: java-1.8.0-openjdk security update
Other sources
The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.Security Fix(es): JDK: Improve Resource Resolving (CVE-2026-60589) JDK: Enhance HTTP Connections (CVE-2026-61308) JDK: Enhance TLS server (CVE-2026-70907) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-1.8.0.504.b01-1.1.el7_9 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-accessibility-1.8.0.504.b01-1.1.el7_9 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-debuginfo-1.8.0.504.b01-1.1.el7_9 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-demo-1.8.0.504.b01-1.1.el7_9 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-devel-1.8.0.504.b01-1.1.el7_9 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-headless-1.8.0.504.b01-1.1.el7_9 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-javadoc-1.8.0.504.b01-1.1.el7_9 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-javadoc-zip-1.8.0.504.b01-1.1.el7_9 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.8.0-openjdk-src-1.8.0.504.b01-1.1.el7_9 - Upgrade
Upgrade
java-1.8.0-openjdkto a version that resolves this vulnerability.Fixed in 8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-61308 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-70907 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-60589
Event History
Frequently Asked Questions
Which environments are covered by this update?
The update applies to java-1.8.0-openjdk packages on the listed Red Hat Enterprise Linux Server Extended Life Cycle Support offerings, including IBM Power little-endian and big-endian systems and IBM z Systems.
Which security areas are addressed?
The update addresses three OpenJDK issues: resource resolving (CVE-2026-60589), HTTP connections (CVE-2026-61308), and TLS server handling (CVE-2026-70907).
Is a specific CVSS score or exploit scenario provided for these issues?
No. The advisory classifies the update as Moderate, but directs readers to the individual CVE pages for impact details, CVSS scores, acknowledgments, and related information.