Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:22139 - Security Advisory
Issued:
2026-06-01
Updated:
2026-06-01

RHSA-2026:22139 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: java-1.8.0-ibm security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

IBM Java SE version 8 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit.

Security Fix(es):

  • openjdk: OpenJDK: Enhance crypto algorithm support (Oracle CPU 2026-04) (CVE-2026-22007)
  • openjdk: OpenJDK: Enhance Path Factories Redux (Oracle CPU 2026-04) (CVE-2026-22016)
  • openjdk: OpenJDK: Improve Kerberos credentialing (Oracle CPU 2026-04) (CVE-2026-22013)
  • openjdk: OpenJDK: Enhance Zip file reading (Oracle CPU 2026-04) (CVE-2026-22018)
  • openjdk: OpenJDK: Enhance certificate chain validation (Oracle CPU 2026-04) (CVE-2026-22021)
  • openjdk: OpenJDK: Enhance key generation (Oracle CPU 2026-04) (CVE-2026-34268)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le

Fixes

  • BZ - 2460038 - CVE-2026-22007 openjdk: Enhance crypto algorithm support (Oracle CPU 2026-04)
  • BZ - 2460039 - CVE-2026-22016 openjdk: Enhance Path Factories Redux (Oracle CPU 2026-04)
  • BZ - 2460040 - CVE-2026-22013 openjdk: Improve Kerberos credentialing (Oracle CPU 2026-04)
  • BZ - 2460041 - CVE-2026-22018 openjdk: Enhance Zip file reading (Oracle CPU 2026-04)
  • BZ - 2460042 - CVE-2026-22021 openjdk: Enhance certificate chain validation (Oracle CPU 2026-04)
  • BZ - 2460043 - CVE-2026-34268 openjdk: Enhance key generation (Oracle CPU 2026-04)

CVEs

  • CVE-2026-22007
  • CVE-2026-22013
  • CVE-2026-22016
  • CVE-2026-22018
  • CVE-2026-22021
  • CVE-2026-34268

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
x86_64
java-1.8.0-ibm-1.8.0.8.65-1.el8_10.x86_64.rpm SHA-256: e15a9ecbdc7e418af5c5c1902e81c896f8065f78058c8a734b19663b535a20c5
java-1.8.0-ibm-demo-1.8.0.8.65-1.el8_10.x86_64.rpm SHA-256: 47ef67b9240479f4fb7df93c685d3b0e699912861dc425e8863c8d95f339009d
java-1.8.0-ibm-devel-1.8.0.8.65-1.el8_10.x86_64.rpm SHA-256: 5f73ff82ab14a1712ca1bf707a78984fc6df6e373abdfe6ee7034989703b71e9
java-1.8.0-ibm-headless-1.8.0.8.65-1.el8_10.x86_64.rpm SHA-256: f1b003cec97d44f910a343b555910ee3b757c7e4d08511308b804852b6636ffd
java-1.8.0-ibm-jdbc-1.8.0.8.65-1.el8_10.x86_64.rpm SHA-256: 15717e9de1b7f2c9f1c2bd1b4f0621d96794e93be801164dce4afaf618668898
java-1.8.0-ibm-plugin-1.8.0.8.65-1.el8_10.x86_64.rpm SHA-256: 8367142ec45d06a0116d404b8a5cbb0b1289c8d16a2943e2986706dfacb44d72
java-1.8.0-ibm-src-1.8.0.8.65-1.el8_10.x86_64.rpm SHA-256: 9229e4ad2702da700bde2d8f7b4274798cec6fb24d47750a5df69daca6919beb
java-1.8.0-ibm-webstart-1.8.0.8.65-1.el8_10.x86_64.rpm SHA-256: bc2ea0134a570f8673a7e1a1babf91f0d26797a47bd878f4d47e3f8a1c0e6ab7

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
s390x
java-1.8.0-ibm-1.8.0.8.65-1.el8_10.s390x.rpm SHA-256: d73a1462fb7bf0718a17695b7ae4fcc46b1e4826f38585754027146f13f37d6b
java-1.8.0-ibm-demo-1.8.0.8.65-1.el8_10.s390x.rpm SHA-256: b9cd70865d3d2c218ac2f481fb2a022de7d33fc3b6981ce69ae42589f653e8d0
java-1.8.0-ibm-devel-1.8.0.8.65-1.el8_10.s390x.rpm SHA-256: 430618c951eeb7289309413c22d15f7016dc6f56693b57fbea216f898aaf58b0
java-1.8.0-ibm-headless-1.8.0.8.65-1.el8_10.s390x.rpm SHA-256: f92ab7b52c38b985f5e8632cee2677798f4b99074c320f901e656d2adf24b217
java-1.8.0-ibm-jdbc-1.8.0.8.65-1.el8_10.s390x.rpm SHA-256: 0d4248b6dfce1eb0ffb2dac23358d9b76730a722d90c7636f353ab5eeadf4485
java-1.8.0-ibm-src-1.8.0.8.65-1.el8_10.s390x.rpm SHA-256: cc6481f1e474c350446096cbec465e0cc88703d1406c76da7ac9ceb60645cda3

Red Hat Enterprise Linux for Power, little endian 8

SRPM
ppc64le
java-1.8.0-ibm-1.8.0.8.65-1.el8_10.ppc64le.rpm SHA-256: 689fb1a767a02fdbc37f0f07cb64f0c263f680ef525d047e9f9f7761adab84af
java-1.8.0-ibm-demo-1.8.0.8.65-1.el8_10.ppc64le.rpm SHA-256: f7b5b8736e5ca5c988315f51b46275c1a060c0914e4914c1685b08e4d1cf6dba
java-1.8.0-ibm-devel-1.8.0.8.65-1.el8_10.ppc64le.rpm SHA-256: 515042b890739ca56dd9ecffaa25202399e5694dc920bb3cfddc9f2ea46895c1
java-1.8.0-ibm-headless-1.8.0.8.65-1.el8_10.ppc64le.rpm SHA-256: 3fd091763b1dcefea49ca21c7eb9b94d04ba6ed69242cdf65e5b4a85507a7d25
java-1.8.0-ibm-jdbc-1.8.0.8.65-1.el8_10.ppc64le.rpm SHA-256: 21bdb94218eefb8e33c50c93ecc42396223d12008bb8d1cca1b12d2a02d9e1f0
java-1.8.0-ibm-plugin-1.8.0.8.65-1.el8_10.ppc64le.rpm SHA-256: fadef1674cde2d5cfbe8c303515206eff6f4bac718ac2c20fe05fafc8a31ece0
java-1.8.0-ibm-src-1.8.0.8.65-1.el8_10.ppc64le.rpm SHA-256: 3dd3a16699ce24062ca63f457c08e06782e0588101bdfdb3d0c5147db7e0410d
java-1.8.0-ibm-webstart-1.8.0.8.65-1.el8_10.ppc64le.rpm SHA-256: 7a261932b48b59582e8595b3925853a2e54b193cea5cbbb4fd9b33d680c42fb0

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility