{"cves":["CVE-2026-22007","CVE-2026-22008","CVE-2026-22013","CVE-2026-22016","CVE-2026-22018","CVE-2026-22021","CVE-2026-23865","CVE-2026-26740","CVE-2026-33416","CVE-2026-33636","CVE-2026-34268","CVE-2026-34282"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[1:25.0.3.0.9-1.0.1]\n- Add Oracle vendor bug URL [Orabug: 34340155]\n\n[1:25.0.3.0.9-1]\n- Update to jdk-25.0.3+9 (GA)\n- Update release notes to 25.0.3+9\n- Update FIPS patch to 57722aab802 version synced with 25.0.3+8\n- Drop local libpng patches now JDK-8372534, JDK-8375063  JDK-8377526 are included upstream\n- Drop local HarfBuzz patch now JDK-8375057 is included upstream\n- Bump freetype version to 2.14.2 following JDK-8373290  JDK-8379158\n- Bump giflib version to 6.1.2 following JDK-8379256  JDK-8380078\n- Bump libpng version to 1.6.57 following JDK-8380959  JDK-8382047\n- Bump zlib version to 1.3.2 following JDK-8378631\n- Bump tzdata version to 2026a following JDK-8379035\n- Add JDK-8375294 EOPNOTSUPP patch ahead of 25.0.4\n- Sync the copy of the portable specfile with the latest update\n- ** This tarball is embargoed until 2026-04-21 @ 1pm PT. **\n- Resolves: RHEL-169620\n- Resolves: RHEL-157091\n- Resolves: RHEL-161217\n- Resolves: RHEL-161333\n- Resolves: RHEL-169613","id":"ELSA-2026-9693","ovalId":"oval:com.oracle.elsa:def:20269693","source":"oracle_linux","title":"ELSA-2026-9693:  java-25-openjdk security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-9693.html"}