BELL-SA-2026:7: Liberica JDK vulnerabilities fixed
Published: August 25, 2026Last modified: September 4, 2026
Description
Multiple security vulnerabilities were discovered in Liberica JDK product family. The following packages are affected: JDK, JDK Lite, Full JDK, JRE, Full JRE. Please follow the instructions in the Solution section to make sure that your system includes all the necessary updates. Additional details for all the related CVEs are available at the links below.
Solution
The following components must be updated to versions listed below ("Fixed" column). For update instructions please refer to the installation guides of the latest versions of the components. The following versions are released under CSPU (Critical Security Patch Update) monthly cadence. Please read more details in our blog post: https://bell-sw.com/blog/liberica-jdk-and-liberica-nik-are-moving-toward-monthly-security-updates/.
Liberica JDK 26.0.2.1 build 1
https://docs.bell-sw.com/liberica-jdk/26.0.2.1b1/general/install-guide/
Liberica JDK 25.0.4.1 build 1
https://docs.bell-sw.com/liberica-jdk/25.0.4.1b1/general/install-guide/
Liberica JDK 21.0.12.1 build 1
https://docs.bell-sw.com/liberica-jdk/21.0.12.1b1/general/install-guide/
Liberica JDK 17.0.20.1 build 1
https://docs.bell-sw.com/liberica-jdk/17.0.20.1b1/general/install-guide/
Liberica JDK 11.0.32.1 build 1
https://docs.bell-sw.com/liberica-jdk/11.0.32.1b1/general/install-guide/
Liberica JDK 8u504 build 1
https://docs.bell-sw.com/liberica-jdk/8u504b1/general/install-guide/
In general, it is sufficient to update all Liberica JDK instances in the system by installing the corresponding updated version of the product (8u504, 11.0.32.1, 17.0.20.1, 21.0.12.1, 25.0.4.1, 26.0.2.1).
| Product | Release | Package | Version |
|---|---|---|---|
| Liberica JDK | 8 | jdk | 8u504+1 |
| jdk-full | 8u504+1 | ||
| jdk-lite | 8u504+1 | ||
| jre | 8u504+1 | ||
| jre-full | 8u504+1 | ||
| 11 | jdk | 11.0.32.1+1 | |
| jdk-full | 11.0.32.1+1 | ||
| jdk-lite | 11.0.32.1+1 | ||
| jre | 11.0.32.1+1 | ||
| jre-full | 11.0.32.1+1 | ||
| 17 | jdk | 17.0.20.1+1 | |
| jdk-full | 17.0.20.1+1 | ||
| jdk-lite | 17.0.20.1+1 | ||
| jre | 17.0.20.1+1 | ||
| jre-full | 17.0.20.1+1 | ||
| 21 | jdk | 21.0.12.1+1 | |
| jdk-full | 21.0.12.1+1 | ||
| jdk-lite | 21.0.12.1+1 | ||
| jre | 21.0.12.1+1 | ||
| jre-full | 21.0.12.1+1 | ||
| 25 | jdk | 25.0.4.1+1 | |
| jdk-full | 25.0.4.1+1 | ||
| jdk-lite | 25.0.4.1+1 | ||
| jre | 25.0.4.1+1 | ||
| jre-full | 25.0.4.1+1 | ||
| 26 | jdk | 26.0.2.1+1 | |
| jdk-full | 26.0.2.1+1 | ||
| jdk-lite | 26.0.2.1+1 | ||
| jre | 26.0.2.1+1 | ||
| jre-full | 26.0.2.1+1 |