[ALSA-2026:40895] Important: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update
Type:
security
Severity:
important
Release date:
2026-07-17
Description:
The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration. Security Fix(es): * jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513) * jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
noarch pki-jackson-databind-2.21.4-1.el9_8.noarch.rpm 5d70286446cdb2416a754f1113a794c5cd48ff1bbec59db6163f2e5e2d29997b
noarch pki-jackson-jaxrs-providers-2.21.4-1.el9_8.noarch.rpm 645bff697f24f756541b9fc6a3c323c13ae54c4cdbe7efd9677c77e135267cd7
noarch pki-jackson-module-jaxb-annotations-2.21.4-1.el9_8.noarch.rpm 71839cc322908f26d651befd7abf661b8a1ac508e56bd55cd19f822c83dd21ba
noarch pki-jackson-core-2.21.4-1.el9_8.noarch.rpm 8435724b5a5b5e037898b15d17880d3c1202e1a82c9b8ef93d9a9bbef6c9c240
noarch pki-jackson-annotations-2.21-1.el9_8.noarch.rpm 8b9b129b1ac53f3c58858b72d8367e01a4bc7b489bec6695e97c6cfbbeb87942
noarch pki-jackson-jaxrs-json-provider-2.21.4-1.el9_8.noarch.rpm e5de871877caaca1638b95c9577c8b0cf3ad1757d1b62c2671288758b8402e31
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.