Fedora Account System
Red Hat Associate
Red Hat Customer
Under certain circumstances, multiple passwords can generate the same crypto keys when using DES PBKDF.
This CVE was fixed in Oracle Java SE 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3. https://www.oracle.com/java/technologies/javase/8u491-relnotes.html#R180_491 https://www.oracle.com/java/technologies/javase/11-0-31-relnotes.html#R11_0_31 https://www.oracle.com/java/technologies/javase/17-0-19-relnotes.html#R17_0_19 https://www.oracle.com/java/technologies/javase/21-0-11-relnotes.html https://www.oracle.com/java/technologies/javase/25-0-3-relnotes.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:22139 https://access.redhat.com/errata/RHSA-2026:22139
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Red Hat Enterprise Linux 10 Red Hat Enterprise Linux 10.2 Extended Update Support Via RHSA-2026:22328 https://access.redhat.com/errata/RHSA-2026:22328