{"cves":["CVE-2025-21502"],"cvss":0.0,"database_specific":{"severity":"MODERATE"},"description":"[1:21.0.6.0.7-1.0.1]\n- Add Oracle vendor bug URL [Orabug: 34340155]\n\n[1:21.0.6.0.7-1]\n- Update to jdk-21.0.6+7 (GA)\n- Update release notes to 21.0.6+7\n- Sync the copy of the portable  devkit specfiles with the latest update\n- Include the latest devkit patches\n- Update README.md to list an easier way of disabling the devkit\n- ** This tarball is embargoed until 2025-01-21 @ 1pm PT. **\n- Resolves: RHEL-73549\n\n[1:21.0.5.0.11-3]\n- Transition to the devkit build by not defining pkgos\n- Exempt x86_64 from the static libs debuginfo test until portable uses an older DWARF version\n- Sync the copy of the portable specfile with the devkit version\n- Include the devkit specfile and patches\n- Document the devkit in README.md\n- Resolves: RHEL-74404\n\n[1:21.0.5.0.11-2]\n- Update to jdk-21.0.5+11 (GA)\n- Update release notes to 21.0.5+11\n- Remove local JDK-8327501  JDK-8328366 backport as this is now upstream.\n- Sync the copy of the portable specfile with the latest update\n- Related: RHEL-61346","id":"ELSA-2025-0426","ovalId":"oval:com.oracle.elsa:def:20250426","source":"oracle_linux","title":"ELSA-2025-0426:  java-21-openjdk security update for RHEL 8.10, 9.4 and 9.5 (MODERATE)","url":"https://linux.oracle.com/errata/ELSA-2025-0426.html"}