Bug#1142997: jansi: CVE-2026-8484
Salvatore Bonaccorso
carnil at debian.org
Wed Jul 29 14:23:40 BST 2026
Source: jansi
Version: 2.4.2-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Control: clone -1 -2
Control: reassign -2 src:jansi-native 1.8-2
Control: retitle -2 jansi-native: CVE-2026-8484
Hi
I'm filling this with RC level as upstream has deprecated the library
and is unmaintained for now. Should we aim to release forky without
it? (thus the severity, if you strongly disagree do downgrade please).
The following vulnerability was published for jansi.
CVE-2026-8484[0]:
| A heap buffer overflow vulnerability exists in the Jansi JNI
| "ioctl()" wrapper due to a lack of size verification for the
| argument array before the system call. This can lead to heap
| corruption and application crashes (DoS). All versions are believed
| to be vulnerable. This project is unmaintained at the time of CVE
| assignment.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-8484
https://www.cve.org/CVERecord?id=CVE-2026-8484
[1] https://cert.pl/en/posts/2026/06/CVE-2026-8484/
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
More information about the pkg-java-maintainers
mailing list