Source: jansi Version: 2.4.2-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Control: clone -1 -2 Control: reassign -2 src:jansi-native 1.8-2 Control: retitle -2 jansi-native: CVE-2026-8484
Hi I'm filling this with RC level as upstream has deprecated the library and is unmaintained for now. Should we aim to release forky without it? (thus the severity, if you strongly disagree do downgrade please). The following vulnerability was published for jansi. CVE-2026-8484[0]: | A heap buffer overflow vulnerability exists in the Jansi JNI | "ioctl()" wrapper due to a lack of size verification for the | argument array before the system call. This can lead to heap | corruption and application crashes (DoS). All versions are believed | to be vulnerable. This project is unmaintained at the time of CVE | assignment. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-8484 https://www.cve.org/CVERecord?id=CVE-2026-8484 [1] https://cert.pl/en/posts/2026/06/CVE-2026-8484/ Please adjust the affected versions in the BTS as needed. Regards, Salvatore __ This is the maintainer address of Debian's Java team <https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-java-maintainers>. Please use [email protected] for discussions and questions.
