{
  "cves": [
    "CVE-2026-22007",
    "CVE-2026-22008",
    "CVE-2026-22013",
    "CVE-2026-22016",
    "CVE-2026-22018",
    "CVE-2026-22021",
    "CVE-2026-23865",
    "CVE-2026-26740",
    "CVE-2026-33416",
    "CVE-2026-33636",
    "CVE-2026-34268",
    "CVE-2026-34282"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[1:25.0.3.0.9-1.0.1]\n- Add Oracle vendor bug URL [Orabug: 34340155]\n\n[1:25.0.3.0.9-1]\n- Update to jdk-25.0.3+9 (GA)\n- Update release notes to 25.0.3+9\n- Update FIPS patch to 57722aab802 version synced with 25.0.3+8\n- Drop local libpng patches now JDK-8372534, JDK-8375063  JDK-8377526 are included upstream\n- Drop local HarfBuzz patch now JDK-8375057 is included upstream\n- Bump freetype version to 2.14.2 following JDK-8373290  JDK-8379158\n- Bump giflib version to 6.1.2 following JDK-8379256  JDK-8380078\n- Bump libpng version to 1.6.57 following JDK-8380959  JDK-8382047\n- Bump zlib version to 1.3.2 following JDK-8378631\n- Bump tzdata version to 2026a following JDK-8379035\n- Add JDK-8375294 EOPNOTSUPP patch ahead of 25.0.4\n- Sync the copy of the portable specfile with the latest update\n- ** This tarball is embargoed until 2026-04-21 @ 1pm PT. **\n- Resolves: RHEL-169620\n- Resolves: RHEL-157091\n- Resolves: RHEL-161217\n- Resolves: RHEL-161333\n- Resolves: RHEL-169613",
  "id": "ELSA-2026-9693",
  "ovalId": "oval:com.oracle.elsa:def:20269693",
  "source": "oracle_linux",
  "title": "ELSA-2026-9693:  java-25-openjdk security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-9693.html"
}