{
  "cves": [
    "CVE-2026-22007",
    "CVE-2026-22013",
    "CVE-2026-22016",
    "CVE-2026-22018",
    "CVE-2026-22021",
    "CVE-2026-23865",
    "CVE-2026-34268"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[1:1.8.0.492.b09-1.0.1]\n- Add Oracle vendor bug URL [Orabug: 34340155]\n\n[1:1.8.0.492.b09-1]\n- Update to 8u492-b09 (GA)\n- Update release notes for 8u492-b09.\n- Add missing CVEs for 8u482.\n- Regenerate JDK-8199936/PR3533 patch following JDK-8374917\n- Regenerate JDK-8186464/RH1433262 patch following JDK-8370986\n- Drop local giflib 5.2.2 patch now JDK-8328999 is included upstream\n- Bump freetype version to 2.14.2 following JDK-8373290  JDK-8379158\n- Bump giflib version to 6.1.2 following JDK-8379256  JDK-8380078\n- Bump LCMS 2 version to 2.15.0 following JDK-8303482\n- Bump libpng version to 1.6.57 following JDK-8375063, JDK-8377526, JDK-8380959  JDK-8382047\n- Sync the copy of the portable specfile with the latest update\n- ** This tarball is embargoed until 2026-04-21 @ 1pm PT. **\n- Resolves: RHEL-169448\n- Resolves: RHEL-133223\n- Resolves: RHEL-146656\n- Resolves: RHEL-148335\n- Resolves: RHEL-148848\n- Resolves: RHEL-161225\n- Resolves: RHEL-161341\n- Resolves: RHEL-157098\n- Resolves: RHEL-157149",
  "id": "ELSA-2026-9683",
  "ovalId": "oval:com.oracle.elsa:def:20269683",
  "source": "oracle_linux",
  "title": "ELSA-2026-9683:  java-1.8.0-openjdk security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-9683.html"
}