-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 24 Apr 2026 11:53:29 +1200
Source: openjdk-25
Built-For-Profiles: noudeb
Architecture: source
Version: 25.0.3+9-1
Distribution: unstable
Urgency: medium
Maintainer: OpenJDK Team <openjdk-25@packages.debian.org>
Changed-By: Vladimir Petko <vladimir.petko@canonical.com>
Changes:
openjdk-25 (25.0.3+9-1) unstable; urgency=medium
.
* OpenJDK 25.0.3 release, Build 9.
- CVEs:
+ CVE-2026-22016: 8370529: Enhance Path Factories Redux
+ CVE-2026-34282: 8374557: Enhance TLS connection handling
+ CVE-2026-22021: 8371830: Enhance certificate chain validation
+ CVE-2026-22013: 8370615: Improve Kerberos credentialing
+ CVE-2026-23865: 8379158: Update FreeType to 2.14.2
+ CVE-2026-22008: 8367463: Improved Arena allocations
+ CVE-2026-22018: 8370986: Enhance Zip file reading
+ CVE-2026-22007: 8369575: Enhance crypto algorithm support
+ CVE-2026-34268: 8371935: Enhance key generation
* d/rules: Check generated files only on amd64. This resolves riscv64
ftbfs, as some architectures change with_check flag.
* Remove openjdk-25-jvmci-jdk binary package.
* d/t/problems.csv: Fix typo in loong64 excluded tests lists.
* Add common GPL and Apache license headers to copyright generator.
* d/copyright: Regenerate.
Checksums-Sha1:
ede7bd14c228f0e5e1960b86448dc86cd97265dd 5126 openjdk-25_25.0.3+9-1.dsc
f757f831f55051a51c3dd670ea0368111b23c53a 613408 openjdk-25_25.0.3+9.orig-googletest.tar.xz
17fc98bab370202407534c12572a0779f15640f3 74084132 openjdk-25_25.0.3+9.orig.tar.xz
378186d326f7467de3ab74cb6a0a11fee18c0ffb 380372 openjdk-25_25.0.3+9-1.debian.tar.xz
372d07d1d51d7310cb9d8d8d1347881d2fd68a5b 20856 openjdk-25_25.0.3+9-1_source.buildinfo
Checksums-Sha256:
678ab6f981df0253426e3bd891f6bdeb59c8e15427ff2a7e8b8258c537b18835 5126 openjdk-25_25.0.3+9-1.dsc
6e6699c442cd6bc008140d159b43a7a39bb811d1ecd380cf3b707cc535e04393 613408 openjdk-25_25.0.3+9.orig-googletest.tar.xz
2dd6c441b49705480db1ebfcd03f43d5dcb7f1d4290e98c1fa6eeefae50cfa07 74084132 openjdk-25_25.0.3+9.orig.tar.xz
b4f149ee66da0f5d0ca1b9e9da77eb169c94d224c407a8caa7065c83e5295282 380372 openjdk-25_25.0.3+9-1.debian.tar.xz
f84175673f3b639a259fc520101dd48a2b3fca87bec21a8ab0f16ce4ac9b953a 20856 openjdk-25_25.0.3+9-1_source.buildinfo
Files:
8edf4d42866a71ae07c7476c89306739 5126 java optional openjdk-25_25.0.3+9-1.dsc
ae1c58d38d39133ebcdc47e09d77a661 613408 java optional openjdk-25_25.0.3+9.orig-googletest.tar.xz
5e0af2bf8269924261b6c0d77c25186d 74084132 java optional openjdk-25_25.0.3+9.orig.tar.xz
5934823551becdda85794a85ce92137c 380372 java optional openjdk-25_25.0.3+9-1.debian.tar.xz
5526cdb3ac4a1b076e41439f8cf9b9ac 20856 java optional openjdk-25_25.0.3+9-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEi0Ab7+QbQ0yQSEMs9jtmipabB8AFAmnqxakACgkQ9jtmipab
B8AzLA//VIk6sFj1BKdjv0TlIYvi0xMzxTgnZpVJQ4G3Nsa8w7jtJ71pFUfmdx89
v4uR6fiWKNadYY6z3ep3vrYvdykUmEXt0PnXnwMrddtPQmGiXwI1VUJY0HTcMgdL
uAqhXJaxausLAGl/XLvmAvrEkDep/dpmT0yse8OXbj75LZI8iRJG15fA8usv92Kx
V5SwYe4lo4sa4h+bD97BD37GTCWs0ACQrtROA13EMfm5S+yvVSdCZylfGQeNrnMq
CX9R15KhWmWdmEUCCUQJ6piLjDrGnzlVU09LM3dQDP8zjAudwHcKsChf59mR3jcq
SIRNfcYEy7+o0k3DzKl7zBvyyrLgMUuny6pssbkNJn632r7aBS/YigRwY/81EVq+
jPlekUXyK4av4SUKY2hkN9PHVX43HWYayk694E0XrCo1LnFEeLhHxT22lxEy7EY5
CWCRCRBeJ99Cafsn8jXt/DruLdPuOALNvj14k5Il0jsYhHNkrYSLO0pxx/YJSCXo
4jHO4k75GzYYf9dyOPnvY/meUkbSEx0BY0WqFmX6ml7ziwCj9Sl/9J3fA3fbTSPV
gWiqyyxuutbJ5/WKag3I/qAAoxSv0Ye1w9n58pZmYBESolQNfJPesBfmsjtqpI1k
TOJZ0GVW1T4tgvZVLGRPuKgn5x6UN/a/AJoOliN2WE2F3vqxjxA=
=B3DF
-----END PGP SIGNATURE-----