Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:52949 - Security Advisory
Issued:
2026-08-10
Updated:
2026-08-10

RHSA-2026:52949 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: java-1.8.0-ibm security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

IBM Java SE version 8 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit.

Security Fix(es):

  • Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize (CVE-2026-41254)
  • openjdk: Enhance TLS certificate handling (CVE-2026-46968)
  • openjdk: Enhance JPEG handling (Oracle CPU 2026-07) (CVE-2026-47010)
  • openjdk: Enhance XBM image support (Oracle CPU 2026-07) (CVE-2026-47021)
  • openjdk: Enhance Jar file processing (Oracle CPU 2026-07) (CVE-2026-47027)
  • openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07) (CVE-2026-47059)
  • openjdk: Enhance Jar handling (Oracle CPU 2026-07) (CVE-2026-47063)
  • openjdk: Improve Nashorn index handling (Oracle CPU 2026-07) (CVE-2026-47057)
  • openjdk: Enhance Dataview Implementation (Oracle CPU 2026-07) (CVE-2026-47058)
  • openjdk: Improve certification checking (Oracle CPU 2026-07) (CVE-2026-60147)
  • Eclipse Foundation OpenJ9: Eclipse OpenJ9: Buffer underflow via tracing method arguments (CVE-2026-16439)
  • Eclipse OMR: Eclipse OMR: Denial of service via improper input validation in arraycmp SIMD (CVE-2026-16243)
  • Eclipse Foundation OpenJ9: Eclipse OpenJ9: Incorrect method delegation can lead to integrity issues (CVE-2026-16441)
  • java-1.8.0-ibm: Arbitrary class loading and instantiation via malicious IIOP server (CVE-2026-8400)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le

Fixes

  • BZ - 2459420 - CVE-2026-41254 Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
  • BZ - 2502751 - CVE-2026-46968 openjdk: Enhance TLS certificate handling
  • BZ - 2502783 - CVE-2026-47010 openjdk: Enhance JPEG handling (Oracle CPU 2026-07)
  • BZ - 2502784 - CVE-2026-47021 openjdk: Enhance XBM image support (Oracle CPU 2026-07)
  • BZ - 2502791 - CVE-2026-47027 openjdk: Enhance Jar file processing (Oracle CPU 2026-07)
  • BZ - 2502792 - CVE-2026-47059 openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07)
  • BZ - 2502793 - CVE-2026-47063 openjdk: Enhance Jar handling (Oracle CPU 2026-07)
  • BZ - 2502794 - CVE-2026-47057 openjdk: Improve Nashorn index handling (Oracle CPU 2026-07)
  • BZ - 2502795 - CVE-2026-47058 openjdk: Enhance Dataview Implementation (Oracle CPU 2026-07)
  • BZ - 2503636 - CVE-2026-60147 openjdk: Improve certification checking (Oracle CPU 2026-07)
  • BZ - 2503798 - CVE-2026-16439 Eclipse Foundation OpenJ9: Eclipse OpenJ9: Buffer underflow via tracing method arguments
  • BZ - 2503988 - CVE-2026-16243 Eclipse OMR: Eclipse OMR: Denial of service via improper input validation in arraycmp SIMD
  • BZ - 2503992 - CVE-2026-16441 Eclipse Foundation OpenJ9: Eclipse OpenJ9: Incorrect method delegation can lead to integrity issues
  • BZ - 2512497 - CVE-2026-8400 java-1.8.0-ibm: Arbitrary class loading and instantiation via malicious IIOP server

CVEs

  • CVE-2026-8400
  • CVE-2026-16243
  • CVE-2026-16439
  • CVE-2026-16441
  • CVE-2026-41254
  • CVE-2026-46968
  • CVE-2026-47010
  • CVE-2026-47021
  • CVE-2026-47027
  • CVE-2026-47057
  • CVE-2026-47058
  • CVE-2026-47059
  • CVE-2026-47063
  • CVE-2026-60147

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
x86_64
java-1.8.0-ibm-1.8.0.8.70-1.el8_10.x86_64.rpm SHA-256: dad0c1db2ad71da3f6b3b4372822558e24b3f77332fbe86c03948be47c9370c5
java-1.8.0-ibm-demo-1.8.0.8.70-1.el8_10.x86_64.rpm SHA-256: a09eb76d348de8afc84b88911e9b52e5cc9e24770c89d57fd883317af122cab6
java-1.8.0-ibm-devel-1.8.0.8.70-1.el8_10.x86_64.rpm SHA-256: ec3f7d68240338f329bb101d8313cf30ed6c195e6842a1927fabd535f52cd6d6
java-1.8.0-ibm-headless-1.8.0.8.70-1.el8_10.x86_64.rpm SHA-256: 79175d7c22c8c48f47ef8ca693a92c36de75841f51b06652a20eb48558ec80bc
java-1.8.0-ibm-jdbc-1.8.0.8.70-1.el8_10.x86_64.rpm SHA-256: c5848a31b36e2e96324ab4bbaafee454605669ed9bd34a7f75f57a887d3b6119
java-1.8.0-ibm-plugin-1.8.0.8.70-1.el8_10.x86_64.rpm SHA-256: d116d37f9d50e4fb3722b73ce6e698af6999e98762a96fba56e113a13756bd30
java-1.8.0-ibm-src-1.8.0.8.70-1.el8_10.x86_64.rpm SHA-256: 7e95b51e7e11bc2f625f19aa83eda0fdf593f7a7b80ea865d0045c6b0860b2b6
java-1.8.0-ibm-webstart-1.8.0.8.70-1.el8_10.x86_64.rpm SHA-256: b4c15513e24051245d7022ac31b0d28ab7ea230630ae4ade754c97da8129ebad

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
s390x
java-1.8.0-ibm-1.8.0.8.70-1.el8_10.s390x.rpm SHA-256: 8fa09fa8456004bcb47e8926331bcca21339e00281b869cfdb31d115382595cd
java-1.8.0-ibm-demo-1.8.0.8.70-1.el8_10.s390x.rpm SHA-256: cd441e4d0497762f142047295bdf7938f2b036deef5016c29b9880fc81432baa
java-1.8.0-ibm-devel-1.8.0.8.70-1.el8_10.s390x.rpm SHA-256: bcee8b282cfa4ee5f6c557f397355c1af6311700fe0eeb9322b65c2077066176
java-1.8.0-ibm-headless-1.8.0.8.70-1.el8_10.s390x.rpm SHA-256: 9a3afd68a859a1fab62b9684f8155c30f2fb43c58dfb9e0d15ed921c8d838b65
java-1.8.0-ibm-jdbc-1.8.0.8.70-1.el8_10.s390x.rpm SHA-256: 1e8a6d8f4d9872d2fbd5b88b103776fb2ee94a9e8fdb4ae82e4e5072af89c550
java-1.8.0-ibm-src-1.8.0.8.70-1.el8_10.s390x.rpm SHA-256: f9b145fd6011f1bfa25f1a940a3b7e6f95297a9d9cc00f3e4f35905fa0bee650

Red Hat Enterprise Linux for Power, little endian 8

SRPM
ppc64le
java-1.8.0-ibm-1.8.0.8.70-1.el8_10.ppc64le.rpm SHA-256: ca0b75d4bc8ade47055f9502e7f4574c8c6df47606b5b2e4a528aad823a1d6d8
java-1.8.0-ibm-demo-1.8.0.8.70-1.el8_10.ppc64le.rpm SHA-256: 4c78744b6f1f2ff91f705d0f86ca63987da716b32cb31157168eec5efbfedfa8
java-1.8.0-ibm-devel-1.8.0.8.70-1.el8_10.ppc64le.rpm SHA-256: a58c8700ebc6327f742d2cbdf365dc8f68df47c384baa5e38094c9f70103085e
java-1.8.0-ibm-headless-1.8.0.8.70-1.el8_10.ppc64le.rpm SHA-256: 3e7b5e805ac1de603b282b804a57493f7a989241a69017854bd1a91268c33215
java-1.8.0-ibm-jdbc-1.8.0.8.70-1.el8_10.ppc64le.rpm SHA-256: e84575321fc3e4fa375c6446dc81b6c8687bf0d1fec78deef4743f336cedb235
java-1.8.0-ibm-plugin-1.8.0.8.70-1.el8_10.ppc64le.rpm SHA-256: 78b80dde4e81b0ee1c112d358204e374a9b6e746a1e63e7747d042e350e8cfd3
java-1.8.0-ibm-src-1.8.0.8.70-1.el8_10.ppc64le.rpm SHA-256: eb2eb8771f4e36860b351f7edb6c68f916ad87c298d7b86bb758091f926df0e6
java-1.8.0-ibm-webstart-1.8.0.8.70-1.el8_10.ppc64le.rpm SHA-256: e8dc360982831cbfe9b92beddf0dab88c710b90cdd15d32a0cff32fce6b495d7

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility