{"cves":["CVE-2026-22007","CVE-2026-22013","CVE-2026-22016","CVE-2026-22018","CVE-2026-22021","CVE-2026-23865","CVE-2026-34268","CVE-2026-34282"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[1:21.0.11.0.10-1.0.1]\n- Add Oracle vendor bug URL [Orabug: 34340155]\n\n[1:21.0.11.0.10-1]\n- Update to jdk-21.0.11+10 (GA)\n- Update release notes to 21.0.11+10\n- Update FIPS patch to feef2dc3ca7 version synced with 21.0.11+9 and adapted to JDK-8244336\n- Bump freetype version to 2.14.2 following JDK-8373290  JDK-8379158\n- Bump giflib version to 6.1.2 following JDK-8379256  JDK-8380078\n- Bump libpng version to 1.6.57 following JDK-8380959  JDK-8382047\n- Bump zlib version to 1.3.2 following JDK-8378631\n- Add JDK-8375294 EOPNOTSUPP patch ahead of 21.0.13\n- Sync the copy of the portable specfile with the latest update\n- ** This tarball is embargoed until 2026-04-21 @ 1pm PT. **\n- Resolves: RHEL-169610\n- Resolves: RHEL-133225\n- Resolves: RHEL-146658\n- Resolves: RHEL-148337\n- Resolves: RHEL-148851\n- Resolves: RHEL-157100\n- Resolves: RHEL-161227\n- Resolves: RHEL-161343\n- Resolves: RHEL-169617","id":"ELSA-2026-9689","ovalId":"oval:com.oracle.elsa:def:20269689","source":"oracle_linux","title":"ELSA-2026-9689:  java-21-openjdk security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-9689.html"}