Jackson-Annotations, Jackson-Core, Jackson-Databind, Jackson-Jaxrs-Providers, And Jackson-Modules-Base Security Update — AlmaLinux 9 (ALSA-2026:40895)
This is a security release for AlmaLinux 9. The fix ships in the current release line (referenced builds: 21.4-1). Update the product on every affected server to the patched release — there is no workaround, and unpatched servers remain exposed until updated.
Команды исправления
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Что это значит по лицензии SharedLicense
Your SharedLicense license itself is not affected — this is a change in AlmaLinux 9 software, not in licensing. Update the product through its standard update channel. Licenses keep working through updates; nothing needs re-issuing or re-activating.
The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration.
Security Fix(es):
* jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-545…
Type:
security
Severity:
important
Release date:
2026-07-17
Description:
The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration.
Security Fix(es):
* jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)
* jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References:
Updated packages listed below:
| Architecture | Package | Checksum |
| noarch | pki-jackson-databind-2.21.4-1.el9_8.noarch.rpm | 5d70286446cdb2416a754f1113a794c5cd48ff1bbec59db6163f2e5e2d29997b |
| noarch | pki-jackson-jaxrs-providers-2.21.4-1.el9_8.noarch.rpm | 645bff697f24f756541b9fc6a3c323c13ae54c4cdbe7efd9677c77e135267cd7 |
| noarch | pki-jackson-module-jaxb-annotations-2.21.4-1.el9_8.noarch.rpm | 71839cc322908f26d651befd7abf661b8a1ac508e56bd55cd19f822c83dd21ba |
| noarch | pki-jackson-core-2.21.4-1.el9_8.noarch.rpm | 8435724b5a5b5e037898b15d17880d3c1202e1a82c9b8ef93d9a9bbef6c9c240 |
| noarch | pki-jackson-annotations-2.21-1.el9_8.noarch.rpm | 8b9b129b1ac53f3c58858b72d8367e01a4bc7b489bec6695e97c6cfbbeb87942 |
| noarch | pki-jackson-jaxrs-json-provider-2.21.4-1.el9_8.noarch.rpm | e5de871877caaca1638b95c9577c8b0cf3ad1757d1b62c2671288758b8402e31 |
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.
Источники
Предупреждения о безопасности
Похожие предупреждения
Проверьте систему на уязвимости
Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.
Проверьте свою систему