{"id":"openSUSE-SU-2026:21423-1","summary":"Security update for jline3","details":"This update for jline3 fixes the following issues:\n\n- CVE-2026-56740: unauthenticated remote memory exhaustion via unbounded Telnet `NEW-ENVIRON` variables (bsc#1269021).\n- CVE-2026-56741: unauthenticated remote DoS via Unbounded Telnet NAWS Terminal Geometry (bsc#1270083).\n\nChanges for jline3:\n\n- Update to upstream version 3.30.15\n\n + fix: guard regex matching against catastrophic backtracking\n   (ReDoS) (#2018, backport of #2012):\n   * Adds SafeRegex utility with TimeoutCharSequence to enforce\n     wall-clock deadlines during regex matching\n   * Fixes 8 locations across terminal, reader, and builtins\n     where user-controlled input could trigger catastrophic\n     backtracking\n   * Addresses GHSA-r2xf-8xr9-62gw, GHSA-2v9w-34q6-wpqx,\n     GHSA-ph9c-7hw9-vhhw, GHSA-5q95-hrpc-m3w3\n + fix: backport security hardening (#1986, #1995):\n   * Create persisted history file with owner-only permissions\n   * Use exclusive create for extracted native library temp files\n + fix: warn on insecure permissions when history file created\n   concurrently\n","modified":"2026-07-24T18:24:31.347482047Z","published":"2026-07-22T16:48:17Z","related":["CVE-2026-56740","CVE-2026-56741"],"upstream":["CVE-2026-56740","CVE-2026-56741"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269021"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270083"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56740"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56741"}],"affected":[{"package":{"name":"jline3","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/jline3&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.30.15-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"jline3-style":"3.30.15-160000.1.1","jline3-curses":"3.30.15-160000.1.1","jline3":"3.30.15-160000.1.1","jline3-terminal-jni":"3.30.15-160000.1.1","jline3-javadoc":"3.30.15-160000.1.1","jline3-jansi":"3.30.15-160000.1.1","jline3-terminal-jansi":"3.30.15-160000.1.1","jline3-builtins":"3.30.15-160000.1.1","jline3-terminal":"3.30.15-160000.1.1","jline3-console":"3.30.15-160000.1.1","jline3-native":"3.30.15-160000.1.1","jline3-reader":"3.30.15-160000.1.1","jline3-jansi-core":"3.30.15-160000.1.1","jline3-remote-telnet":"3.30.15-160000.1.1","jline3-terminal-jna":"3.30.15-160000.1.1","jline3-console-ui":"3.30.15-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21423-1.json"}}],"schema_version":"1.7.5"}