Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90095.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-90095
Upstream
Published
2026-06-16T12:16:26Z
Modified
2026-08-30T05:24:52Z
Summary
CVE-2026-8484 affecting package jansi 2.4.0-1
Details

A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS). All versions are believed to be vulnerable. This project is unmaintained at the time of CVE assignment.

References

Affected packages

Azure Linux:3 / jansi

Package

Name
jansi
Purl
pkg:rpm/azure-linux/jansi

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.4.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90095.json"