{"id":"openSUSE-SU-2026:22009-1","summary":"Security update for jline3","details":"This update for jline3 fixes the following issue:\n\nUpdate to upstream version 3.30.17:\n\n * Security Fixes\n + Native Stack Buffer Overflow in Public INPUT_RECORD.memmove\n JNI Method (Windows) (GHSA-6r3w-6jpj-x5w6)\n + Authenticated SSH Shell Channel Resource Leak via Null or\n Non-Numeric PTY Dimensions (GHSA-7h86-pjwh-gpqj)\n + Authenticated SSH DoS via Unbounded Window-Change Terminal\n Geometry (GHSA-m935-wqpj-pvp3)\n + TCP Socket File Descriptor Leak When Maximum Connections\n Reached (GHSA-c87g-867h-cqr6)\n * Bug Fixes\n + strip control characters from file names in posix builtins\n + bound !# history expansion to prevent exponential blowup\n + verify server host keys in the ssh client builtin\n + address remaining security vulnerabilities reported by\n AFINE/CERT.PL\n + backport security fixes from master\n + backport security fixes to 3.x (path traversal + DSR plain\n text)\n + strip control characters from ssh banner and prompts\n * Dependency updates\n + bump com.diffplug.spotless:spotless-maven-plugin from 3.8.0 to\n 3.10.2\n + bump slf4j.version from 2.0.18 to 2.0.19\n + bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.6\n to 3.6.0\n + bump org.apache.maven.plugins:maven-compiler-plugin from\n 3.15.0 to 3.16.0\n + bump org.apache.felix:maven-bundle-plugin from 6.0.2 to 6.1.2\n + bump actions/setup-java from 5 to 6.0.0\n + bump org.graalvm.sdk:graal-sdk from 25.1.3 to 25.3.4.1\n + bump com.mycila:license-maven-plugin from 5.0.0 to 5.1.2\n + bump org.easymock:easymock from 5.6.0 to 5.7.0\n + bump com.google.jimfs:jimfs from 1.3.1 to 1.3.2\n + bump org.apache.maven.wrapper:maven-wrapper from 3.3.2 to\n 3.3.4\n + bump org.apache.maven:apache-maven from 4.0.0-rc-3 to\n 4.0.0-rc-6\n + bump eu.maveniverse.maven.njord:extension3 from 0.9.9 to\n 0.9.10\n + bump com.palantir.javaformat:palantir-java-format from 2.96.0\n to 2.97.0\n + bump release-drafter/release-drafter from 7.6.0 to 7.7.0\n + bump groovy.version from 4.0.32 to 4.0.33\n + bump release-drafter/release-drafter from 7 to 7.6.0\n + bump org.apache.maven.plugins:maven-jar-plugin from 3.5.0 to\n 3.5.1\n- Update to upstream version 3.30.16\n * bugfix release with security hardening, SSH agent forwarding\n fix, and terminal compatibility improvements.\n * Breaking Changes\n + SSH agent forwarding is no longer enabled by default;\n pass -A to explicitly request it\n + reject overlong hex components in OSC color responses\n + strip OSC and other escape sequences in ansiAppend\n + search multiple lib paths for versioned libutil.so\n + use Path.resolve instead of URI.resolve in cat and sort to\n prevent SSRF\n + check closed flag in PtyInputStream to prevent hang on empty\n input\n + confine ConfigurationPath lookups to the config directory\n + disable Read File command in nano restricted mode\n + drain buffered data before EOF in NonBlockingPumpInputStream\n + look up openpty in libc.so.6 for glibc 2.34+\n + guard styleMatches and highlighter rules against ReDoS\n + backport telnet DoS mitigations (GHSA-47qp, GHSA-2r2c)\n + propagate EOF in PtyInputStream to avoid infinite loop\n + bump org.apache.ivy:ivy from 2.5.3 to 2.6.0\n + bump actions/setup-node from 6 to 7\n + bump com.palantir.javaformat:palantir-java-format from 2.94.0\n to 2.96.0\n + bump sshd.version from 2.18.0 to 2.19.0\n + bump org.codehaus.gmavenplus:gmavenplus-plugin from 5.0.0 to\n 5.1.0\n + bump org.graalvm.sdk:graal-sdk from 25.0.3 to 25.1.3\n + bump com.diffplug.spotless:spotless-maven-plugin\n","modified":"2026-10-03T17:23:12.429960332Z","published":"2026-10-01T12:14:32Z","references":[{"type":"ADVISORY"}],"affected":[{"package":{"name":"jline3","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/jline3&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.30.17-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"jline3-console-ui":"3.30.17-160000.1.1","jline3-terminal-jni":"3.30.17-160000.1.1","jline3-console":"3.30.17-160000.1.1","jline3-style":"3.30.17-160000.1.1","jline3-terminal":"3.30.17-160000.1.1","jline3-terminal-jansi":"3.30.17-160000.1.1","jline3-terminal-jna":"3.30.17-160000.1.1","jline3-remote-telnet":"3.30.17-160000.1.1","jline3-native":"3.30.17-160000.1.1","jline3-curses":"3.30.17-160000.1.1","jline3-javadoc":"3.30.17-160000.1.1","jline3-reader":"3.30.17-160000.1.1","jline3":"3.30.17-160000.1.1","jline3-jansi-core":"3.30.17-160000.1.1","jline3-jansi":"3.30.17-160000.1.1","jline3-builtins":"3.30.17-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:22009-1.json"}}],"schema_version":"1.9.0"}