Bug 2403064 (CVE-2025-61748) - CVE-2025-61748 openjdk: Enhance String handling (Oracle CPU 2025-10)
Summary: CVE-2025-61748 openjdk: Enhance String handling (Oracle CPU 2025-10)
Keywords:
Status: NEW
Alias: CVE-2025-61748
Deadline: 2025-10-21
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-10-10 11:41 UTC by OSIDB Bzimport
Modified: 2025-10-24 13:47 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-10-10 11:41:23 UTC
After JDK-8282429 (19) certain Strings built using StringBuilder
return an incorrect result for String.equals() checks.

Comment 2 Michal Findra 2025-10-24 13:40:42 UTC
OpenJDK-21 upstream commit:
https://github.com/openjdk/jdk21u/commit/23bd6b50dbbf33975c21c122f8b7e4c7b0d57fdc


Note You need to log in before you can comment on or make changes to this bug.