openSUSE-SU-2026:22009-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:22009-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:22009-1
Published
2026-10-01T12:14:32Z
Modified
2026-10-03T17:23:12Z
Summary
Security update for jline3
Details

This update for jline3 fixes the following issue:

Update to upstream version 3.30.17:

  • Security Fixes
  • Native Stack Buffer Overflow in Public INPUT_RECORD.memmove JNI Method (Windows) (GHSA-6r3w-6jpj-x5w6)
  • Authenticated SSH Shell Channel Resource Leak via Null or Non-Numeric PTY Dimensions (GHSA-7h86-pjwh-gpqj)
  • Authenticated SSH DoS via Unbounded Window-Change Terminal Geometry (GHSA-m935-wqpj-pvp3)
  • TCP Socket File Descriptor Leak When Maximum Connections Reached (GHSA-c87g-867h-cqr6)
  • Bug Fixes
  • strip control characters from file names in posix builtins
  • bound !# history expansion to prevent exponential blowup
  • verify server host keys in the ssh client builtin
  • address remaining security vulnerabilities reported by AFINE/CERT.PL
  • backport security fixes from master
  • backport security fixes to 3.x (path traversal + DSR plain text)
  • strip control characters from ssh banner and prompts
  • Dependency updates
  • bump com.diffplug.spotless:spotless-maven-plugin from 3.8.0 to 3.10.2
  • bump slf4j.version from 2.0.18 to 2.0.19
  • bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.6 to 3.6.0
  • bump org.apache.maven.plugins:maven-compiler-plugin from 3.15.0 to 3.16.0
  • bump org.apache.felix:maven-bundle-plugin from 6.0.2 to 6.1.2
  • bump actions/setup-java from 5 to 6.0.0
  • bump org.graalvm.sdk:graal-sdk from 25.1.3 to 25.3.4.1
  • bump com.mycila:license-maven-plugin from 5.0.0 to 5.1.2
  • bump org.easymock:easymock from 5.6.0 to 5.7.0
  • bump com.google.jimfs:jimfs from 1.3.1 to 1.3.2
  • bump org.apache.maven.wrapper:maven-wrapper from 3.3.2 to 3.3.4
  • bump org.apache.maven:apache-maven from 4.0.0-rc-3 to 4.0.0-rc-6
  • bump eu.maveniverse.maven.njord:extension3 from 0.9.9 to 0.9.10
  • bump com.palantir.javaformat:palantir-java-format from 2.96.0 to 2.97.0
  • bump release-drafter/release-drafter from 7.6.0 to 7.7.0
  • bump groovy.version from 4.0.32 to 4.0.33
  • bump release-drafter/release-drafter from 7 to 7.6.0
  • bump org.apache.maven.plugins:maven-jar-plugin from 3.5.0 to 3.5.1
  • Update to upstream version 3.30.16
  • bugfix release with security hardening, SSH agent forwarding fix, and terminal compatibility improvements.
  • Breaking Changes
  • SSH agent forwarding is no longer enabled by default; pass -A to explicitly request it
  • reject overlong hex components in OSC color responses
  • strip OSC and other escape sequences in ansiAppend
  • search multiple lib paths for versioned libutil.so
  • use Path.resolve instead of URI.resolve in cat and sort to prevent SSRF
  • check closed flag in PtyInputStream to prevent hang on empty input
  • confine ConfigurationPath lookups to the config directory
  • disable Read File command in nano restricted mode
  • drain buffered data before EOF in NonBlockingPumpInputStream
  • look up openpty in libc.so.6 for glibc 2.34+
  • guard styleMatches and highlighter rules against ReDoS
  • backport telnet DoS mitigations (GHSA-47qp, GHSA-2r2c)
  • propagate EOF in PtyInputStream to avoid infinite loop
  • bump org.apache.ivy:ivy from 2.5.3 to 2.6.0
  • bump actions/setup-node from 6 to 7
  • bump com.palantir.javaformat:palantir-java-format from 2.94.0 to 2.96.0
  • bump sshd.version from 2.18.0 to 2.19.0
  • bump org.codehaus.gmavenplus:gmavenplus-plugin from 5.0.0 to 5.1.0
  • bump org.graalvm.sdk:graal-sdk from 25.0.3 to 25.1.3
  • bump com.diffplug.spotless:spotless-maven-plugin
References

Affected packages

openSUSE:Leap 16.0 / jline3

Package

Name
jline3
Purl
pkg:rpm/opensuse/jline3&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.30.17-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "jline3":  "3.30.17-160000.1.1",
            "jline3-builtins":  "3.30.17-160000.1.1",
            "jline3-console":  "3.30.17-160000.1.1",
            "jline3-console-ui":  "3.30.17-160000.1.1",
            "jline3-curses":  "3.30.17-160000.1.1",
            "jline3-jansi":  "3.30.17-160000.1.1",
            "jline3-jansi-core":  "3.30.17-160000.1.1",
            "jline3-javadoc":  "3.30.17-160000.1.1",
            "jline3-native":  "3.30.17-160000.1.1",
            "jline3-reader":  "3.30.17-160000.1.1",
            "jline3-remote-telnet":  "3.30.17-160000.1.1",
            "jline3-style":  "3.30.17-160000.1.1",
            "jline3-terminal":  "3.30.17-160000.1.1",
            "jline3-terminal-jansi":  "3.30.17-160000.1.1",
            "jline3-terminal-jna":  "3.30.17-160000.1.1",
            "jline3-terminal-jni":  "3.30.17-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:22009-1.json"