Source: jansi
Version: 2.4.2-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: clone -1 -2 
Control: reassign -2 src:jansi-native 1.8-2
Control: retitle -2 jansi-native: CVE-2026-8484

Hi

I'm filling this with RC level as upstream has deprecated the library
and is unmaintained for now. Should we aim to release forky without
it? (thus the severity, if you strongly disagree do downgrade please).

The following vulnerability was published for jansi.

CVE-2026-8484[0]:
| A heap buffer overflow vulnerability exists in the Jansi JNI
| "ioctl()" wrapper due to a lack of size verification for the
| argument array before the system call. This can lead to heap
| corruption and application crashes (DoS). All versions are believed
| to be vulnerable. This project is unmaintained at the time of CVE
| assignment.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-8484
    https://www.cve.org/CVERecord?id=CVE-2026-8484
[1] https://cert.pl/en/posts/2026/06/CVE-2026-8484/

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore
__
This is the maintainer address of Debian's Java team
<https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-java-maintainers>.
 Please use
[email protected] for discussions and questions.

Reply via email to