Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 471
Alerts This Week
Warning Icon 1 471

openSUSE jline3 Important Remote DoS Memory Exhaustion 2026-21423-1

opensuse
Calendar Grey July 24, 2026
Scroller Opensuse
This update addresses critical exploits in jline3 affecting openSUSE, ensuring the integrity of your system. Resolve the threats now.
openSUSE released an important security update for jline3, addressing two vulnerabilities related to unauthenticated remote memory exhaustion and DoS attacks, along with multiple b...

Description

This update for jline3 fixes the following issues:

- CVE-2026-56740: unauthenticated remote memory exhaustion via unbounded Telnet `NEW-ENVIRON` variables (bsc#1269021).

- CVE-2026-56741: unauthenticated remote DoS via Unbounded Telnet NAWS Terminal Geometry (bsc#1270083).

Changes for jline3:

- Update to upstream version 3.30.15

+ fix: guard regex matching against catastrophic backtracking

(ReDoS) (#2018, backport of #2012):

* Adds SafeRegex utility with TimeoutCharSequence to enforce

wall-clock deadlines during regex matching

* Fixes 8 locations across terminal, reader, and builtins

where user-controlled input could trigger catastrophic

backtracking

* Addresses GHSA-r2xf-8xr9-62gw, GHSA-2v9w-34q6-wpqx,

GHSA-ph9c-7hw9-vhhw, GHSA-5q95-hrpc-m3w3

+ fix: backport security hardening (#1986, #1995):

* Create persisted history file with owner-only permissions

* Use exclusive create for extracted native library temp files

+ fix: warn on insecure...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

jline3-3.30.15-160000.1.1

jline3-builtins-3.30.15-160000.1.1

jline3-console-3.30.15-160000.1.1

jline3-console-ui-3.30.15-160000.1.1

jline3-curses-3.30.15-160000.1.1

jline3-jansi-3.30.15-160000.1.1

jline3-jansi-core-3.30.15-160000.1.1

jline3-javadoc-3.30.15-160000.1.1

jline3-native-3.30.15-160000.1.1

jline3-reader-3.30.15-160000.1.1

jline3-remote-telnet-3.30.15-160000.1.1

jline3-style-3.30.15-160000.1.1

jline3-terminal-3.30.15-160000.1.1

jline3-terminal-jansi-3.30.15-160000.1.1

jline3-terminal-jna-3.30.15-160000.1.1

jline3-terminal-jni-3.30.15-160000.1.1

References

* bsc#1269021

* bsc#1270083

References:

* https://www.suse.com/security/cve/CVE-2026-56740.html

* https://www.suse.com/security/cve/CVE-2026-56741.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21423-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.