CVE-2026-10037

NameCVE-2026-10037
DescriptionA sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openjdk-11 (PTS)sid11.0.32.1+1-1fixed
openjdk-17 (PTS)bookworm17.0.19+10-1~deb12u2fixed
bookworm (security)17.0.20.1+1-1~deb12u1fixed
sid17.0.20.1+1-1fixed
openjdk-21 (PTS)trixie21.0.11+10-1~deb13u2fixed
trixie (security)21.0.12.1+1-1~deb13u1fixed
forky, sid21.0.12.1+1-1fixed
openjdk-25 (PTS)trixie25.0.3+9-2~deb13u1fixed
trixie (security)25.0.4.1+1-1~deb13u1fixed
forky25.0.4+7-1fixed
sid25.0.4.1+1-1fixed
openjdk-26 (PTS)forky, sid26.0.2.1+1-1fixed
openjdk-8 (PTS)sid8u504-ga-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
openjdk-11source(unstable)(not affected)
openjdk-17source(unstable)(not affected)
openjdk-21source(unstable)(not affected)
openjdk-25source(unstable)(not affected)
openjdk-26source(unstable)(not affected)
openjdk-8source(unstable)(not affected)

Notes

- openjdk-26 <not-affected> (Ubuntu-specific change)
- openjdk-25 <not-affected> (Ubuntu-specific change)
- openjdk-21 <not-affected> (Ubuntu-specific change)
- openjdk-17 <not-affected> (Ubuntu-specific change)
- openjdk-11 <not-affected> (Ubuntu-specific change)
- openjdk-8 <not-affected> (Ubuntu-specific change)
https://bugs.launchpad.net/ubuntu/+source/openjdk-25/+bug/2153100
Debian doesn't install a desktop file with a MIME handler

Search for package or bug name: Reporting problems