Release date:
2026-08-12 13:26:50 UTC
Description:
- CVE-2025-21587: constant-time RSA PKCS#1 v1.5 unpadding and TLS premaster secret version check (JDK-8337692)
- CVE-2026-22016: apply secure processing to the DocumentBuilderFactory used by XPath evaluation (JDK-8370529, JDK-8356294)
- CVE-2026-47063: enforce RFC 5652 signed attributes and RFC 3161 id-ct-TSTInfo content type (JDK-8381049)
- CVE-2026-21945: restrict AIA caIssuer URIs via com.sun.security.allowedAIALocations (JDK-8368032)
Updated packages:
-
java-1.7.0-openjdk-1.7.0.321-2.6.28.2.amzn2.0.3.tuxcare.els5.x86_64.rpm
sha:e3658bc9959ff791cbe4d47624ec80b77af9efe18816d1ae82145e1f612439ae
-
java-1.7.0-openjdk-accessibility-1.7.0.321-2.6.28.2.amzn2.0.3.tuxcare.els5.x86_64.rpm
sha:6bcd160a6c6a0fd9f13c1caf7ba4ac604c8be3b7223c11f8cec49ce04616ace8
-
java-1.7.0-openjdk-demo-1.7.0.321-2.6.28.2.amzn2.0.3.tuxcare.els5.x86_64.rpm
sha:a9f84811fd726c45bdd486cf9673200776dcd52b2342b707e191ac3e42d94bad
-
java-1.7.0-openjdk-devel-1.7.0.321-2.6.28.2.amzn2.0.3.tuxcare.els5.x86_64.rpm
sha:cc0643093ca1e1a36f8bc1d09d44008364092d7cc05b3c6410b1c90dca9a508d
-
java-1.7.0-openjdk-headless-1.7.0.321-2.6.28.2.amzn2.0.3.tuxcare.els5.x86_64.rpm
sha:892de0623958d9e7f388f1528d233e11b1ed6dab36022e2ec918f383c84ed014
-
java-1.7.0-openjdk-javadoc-1.7.0.321-2.6.28.2.amzn2.0.3.tuxcare.els5.noarch.rpm
sha:e9597795d551d40251d76d0122d3df944350a74c172f1ad0af4eff3e39c592d5
-
java-1.7.0-openjdk-src-1.7.0.321-2.6.28.2.amzn2.0.3.tuxcare.els5.x86_64.rpm
sha:56dfd7c73010dcce6b1149d3344336ed44578eb1d6947f11a4cbcdf680b609a0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.