ELA-1708-1 openjdk-11 security update

multiple vulnerabilities

2026-05-06
Packageopenjdk-11
Version11.0.31+11-1~deb10u1 (buster)
Related CVEs CVE-2026-22007 CVE-2026-22013 CVE-2026-22016 CVE-2026-22018 CVE-2026-22021 CVE-2026-34268 CVE-2026-34282


Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect generation of cryptographic keys, denial of service, information disclosure, XEE/XEE attacks or incorrect validation of Kerberos credentials.



For Debian 10 buster, these problems have been fixed in version 11.0.31+11-1~deb10u1.

We recommend that you upgrade your openjdk-11 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.