{
  "cves": [
    "CVE-2026-41254",
    "CVE-2026-46917",
    "CVE-2026-46968",
    "CVE-2026-47010",
    "CVE-2026-47021",
    "CVE-2026-47027",
    "CVE-2026-47059",
    "CVE-2026-47063",
    "CVE-2026-60147"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[1:17.0.20.0.8-1.1.0.1]\n- Add Oracle vendor bug URL [Orabug: 34340155]\n\n[1:17.0.20.0.8-1.1]\n- Sync java-17-openjdk-portable.specfile from openjdk-portable-rhel-8\n- Add .0 to prelease\n\n[1:17.0.20.0.8-1.1]\n- Sync NEWS from private-gnu_andrew-rhel-8.5-vanilla\n\n[1:17.0.20.0.8-1.1]\n- Set tzdata requires and build requires to 2026b\n- Set fipsver to 821eb26f706\n- Delete comments about patch macro syntax\n- Set bundled freetype version to 2.14.3\n- Set bundled giflib version to 6.1.3\n- Set bundled harfbuzz version to 14.2.0\n- Set bundled lcms2 version to 2.19.1\n- Set bundled libpng version to 1.6.58\n\n[1:17.0.20.0.8-1.1]\n- Specify portablerelease and rpmrelease (always 0 for portables) in the Release field (OPENJDK-4876)\n\n[1:17.0.20.0.8-1]\n- Update to jdk-17.0.20+8 (GA)\n- Add to .gitignore openjdk-17.0.20+8.tar.xz\n- Set updatever to 20\n- Set buildver to 8\n- Update sources to openjdk-17.0.20+8.tar.xz\n- ** This tarball is embargoed until 2026-07-21 @ 1pm PT. **\n- Resolves: RHEL-188876",
  "id": "ELSA-2026-42887",
  "ovalId": "oval:com.oracle.elsa:def:202642887",
  "source": "oracle_linux",
  "title": "ELSA-2026-42887:  java-17-openjdk security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-42887.html"
}