| Name | CVE-2026-10037 |
| Description | A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| openjdk-11 (PTS) | sid | 11.0.32.1+1-1 | fixed |
| openjdk-17 (PTS) | bookworm | 17.0.19+10-1~deb12u2 | fixed |
| bookworm (security) | 17.0.20.1+1-1~deb12u1 | fixed |
| sid | 17.0.20.1+1-1 | fixed |
| openjdk-21 (PTS) | trixie | 21.0.11+10-1~deb13u2 | fixed |
| trixie (security) | 21.0.12.1+1-1~deb13u1 | fixed |
| forky, sid | 21.0.12.1+1-1 | fixed |
| openjdk-25 (PTS) | trixie | 25.0.3+9-2~deb13u1 | fixed |
| trixie (security) | 25.0.4.1+1-1~deb13u1 | fixed |
| forky | 25.0.4+7-1 | fixed |
| sid | 25.0.4.1+1-1 | fixed |
| openjdk-26 (PTS) | forky, sid | 26.0.2.1+1-1 | fixed |
| openjdk-8 (PTS) | sid | 8u504-ga-1 | fixed |
The information below is based on the following data on fixed versions.
Notes
- openjdk-26 <not-affected> (Ubuntu-specific change)
- openjdk-25 <not-affected> (Ubuntu-specific change)
- openjdk-21 <not-affected> (Ubuntu-specific change)
- openjdk-17 <not-affected> (Ubuntu-specific change)
- openjdk-11 <not-affected> (Ubuntu-specific change)
- openjdk-8 <not-affected> (Ubuntu-specific change)
https://bugs.launchpad.net/ubuntu/+source/openjdk-25/+bug/2153100
Debian doesn't install a desktop file with a MIME handler