IBM Support

IJ58270: PQC (ML-KEM) HYBRID ALGORITHMS INCORRECTLY ADVERTISED AS SUPPORTED ON 32-BIT JVMS

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Error Message: 32-bit JVM incorrectly advertises support for PQC
    hybrid algorithms (X25519MLKEM768, SecP256r1MLKEM768,
    SecP384r1MLKEM1024) which are not supported
    .
    Stack Trace: N/A
    .
    32-bit JVM does not support PQC hybrid algorithms but
    incorrectly advertises them during TLS handshake
    

Local fix

  • Add X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024 to the
    jdk.disabled.namedCurves property on the 32-bit JVM to prevent
    it from being advertised
    

Problem summary

  • 32-bit JVMs do not support PQC hybrid algorithms such as
    X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024 but
    incorrectly advertise support for them during TLS handshake.
    This causes connection failures when clients attempt to use
    these algorithms.
    

Problem conclusion

  • JSSE is updated to ensure 32-bit JVMs do not advertise PQC
    hybrid algorithm support.
    A fix is made to: ibmjsseprovider2.jar
    RTC Problem Report is: 154026
    GIT issue is: JSSE#407
    JVMs affected: Java 8.0 (32-bit)
    The fix was delivered for: Java 8 SR8 FP70
    The affected jars: ibmjsseprovider2.jar
    Build level: 8.0 build_20260427--668
    .
    This APAR will be fixed in the following Releases:
    .
    IBM Semeru Runtimes
    IBM SDK, Java Technology Edition
       8    SR8 FP70  (8.0.8.70)
    .
    Downloads and supplementary documentation can be found at the
    following locations:
    - For non z/OS operating systems:
      - IBM Semeru Runtimes, Version 11 and later
        https://www.ibm.com/semeru-runtimes/downloads/
      - IBM SDK, Java Technology Edition, Version 8
        https://www.ibm.com/support/pages/java-sdk-downloads/
    - For the z/OS operating system:
      - Java SDK Products on z/OS
        https://www.ibm.com/support/pages/java-sdk-products-zos
    

Temporary fix

  • N/A
    

Comments

APAR Information

  • APAR number

    IJ58270

  • Reported component name

    SECURITY

  • Reported component ID

    620700125

  • Reported release

    270

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2026-05-09

  • Closed date

    2026-05-09

  • Last modified date

    2026-05-09

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    SECURITY

  • Fixed component ID

    620700125

Applicable component levels

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"270","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}}]

Document Information

Modified date:
13 May 2026