Re: Security updates for JDK
"Rainer Fiebig" ([email protected] via blfs-dev Mailing List) <[email protected]> Tue, 18 Nov 2025 20:39:43 +0100
| Newsgroups | gmane.linux.lfs.beyond.devel |
|---|---|
| Message-ID | <[email protected]> |
Am 04.11.25 um 21:15 schrieb "Douglas R. Reno" ([email protected] via blfs-dev Mailing List): > Good afternoon, > > I'm catching up on things after an extended family emergency and other > problems took me out of the game for a while (and to be fair, I'm still > not 100% yet, but things need to be taken care of). > > While I was out, new Java security updates became available on October > 21st. These updates fix several vulnerabilities, some of which more > severe than normal and may affect standard usage of programs such as > Libreoffice and fop. Some details on the vulnerabilities: > > - CVE-2025-53066 in the JAXP component, affecting multiple protocols. > It's a network exploitable vulnerability rated as High, and is extremely > trivial to exploit (and I have seen this happen on some Minecraft > servers that I host). The biggest risk is data exfiltration of any file > that Java can read. No risk to system integrity or availability though. > This can happen silently though with no user interaction, and no > privileges are required either. There's several different attack vectors > which this can be possibly exploited. > > - CVE-2025-53057 in the Security component. That's rated as Medium, and > has High attack complexity - but it does allow for a complete and total > SSL bypass. > > - CVE-2025-61748 in the Libraries component. That's rated as Low, and > can cause some integrity problems with certificates being trusted that > are not supposed to be trusted, as well as some other unlisted impacts. > > All three of these vulnerabilities are exploitable remotely with no user > interaction or privileges required. The first one is particular > egregious, but I have some other security updates and tickets that I > need to handle first. In the case of the three Minecraft servers that > were affected that I host, the attackers attempted to read /etc/passwd > and other sensitive system information. > > Before I file a ticket though, there's a problem that I need some advice > on. Java 25 is the latest version, and is the latest LTS. However, it's > got some major problems - notably that regressions cause applications > like Apache ANT and Fop (https://bugs.openjdk.org/browse/JDK-8368356) to > not work correctly, and even though they were reported and acknowledged > by OpenJDK back in September, they have not been resolved yet. I will > also note that very few of my prebuilt Java binaries run either because > they accidentally changed the class version in 25.0.1. > > Because of the security risks involved and the instability of the Java > 25 series so far, I would like to suggest downgrading the books back to > Java 21. It's the stable LTS, and we know everything in the book should > work with it. I don't feel comfortable leaving 24 in the book because of > CVE-2025-53066. > > Can I have some opinions on this please? Do we go back to 21, or upgrade > to 25 and spend time with upstreams trying to make the newer version > work... Downgrading from 24 to 21 isn't as straightforward as going from 24 to 25. So for those who don't use Ant/Fop: is there anything else that would speak against upgrading to 25? Thanks. Rainer -- http://lists.linuxfromscratch.org/sympa/info/blfs-dev Unsubscribe: See the above information page