vulnerability

Oracle Linux: CVE-2026-26740: ELSA-2026-9693: java-25-openjdk security update (IMPORTANT)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Mar 18, 2026
Added
Apr 24, 2026
Modified
Apr 24, 2026

Description

A flaw was found in giflib. A remote attacker can exploit a buffer overflow vulnerability in the EGifGCBToExtension function by providing a specially crafted Graphics Control Extension (GCE) block. This allows overwriting an existing GCE block without proper size validation, leading to a denial of service (DoS) on the system.

Solutions

oracle-linux-upgrade-java-25-openjdkoracle-linux-upgrade-java-25-openjdk-crypto-adapteroracle-linux-upgrade-java-25-openjdk-crypto-adapter-fastdebugoracle-linux-upgrade-java-25-openjdk-crypto-adapter-slowdebugoracle-linux-upgrade-java-25-openjdk-demooracle-linux-upgrade-java-25-openjdk-demo-fastdebugoracle-linux-upgrade-java-25-openjdk-demo-slowdebugoracle-linux-upgrade-java-25-openjdk-develoracle-linux-upgrade-java-25-openjdk-devel-fastdebugoracle-linux-upgrade-java-25-openjdk-devel-slowdebugoracle-linux-upgrade-java-25-openjdk-fastdebugoracle-linux-upgrade-java-25-openjdk-headlessoracle-linux-upgrade-java-25-openjdk-headless-fastdebugoracle-linux-upgrade-java-25-openjdk-headless-slowdebugoracle-linux-upgrade-java-25-openjdk-javadocoracle-linux-upgrade-java-25-openjdk-javadoc-ziporacle-linux-upgrade-java-25-openjdk-jmodsoracle-linux-upgrade-java-25-openjdk-jmods-fastdebugoracle-linux-upgrade-java-25-openjdk-jmods-slowdebugoracle-linux-upgrade-java-25-openjdk-slowdebugoracle-linux-upgrade-java-25-openjdk-srcoracle-linux-upgrade-java-25-openjdk-src-fastdebugoracle-linux-upgrade-java-25-openjdk-src-slowdebugoracle-linux-upgrade-java-25-openjdk-static-libsoracle-linux-upgrade-java-25-openjdk-static-libs-fastdebugoracle-linux-upgrade-java-25-openjdk-static-libs-slowdebug
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.