Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

SUSE jline3 Important Memory Exhaustion DoS Vuln 2026-22856-1

suse
Calendar Grey July 27, 2026
Scroller Suse
An important security update for jline3 addressing memory exhaustion and DoS vulnerabilities on SUSE Linux Enterprise.
SUSE released a security update for jline3 addressing two vulnerabilities that could lead to remote memory exhaustion and denial of service, applicable to specific SUSE Linux Enter...

Summary

## This update for jline3 fixes the following issues: * CVE-2026-56740: unauthenticated remote memory exhaustion via unbounded Telnet `NEW-ENVIRON` variables (bsc#1269021). * CVE-2026-56741: unauthenticated remote DoS via Unbounded Telnet NAWS Terminal Geometry (bsc#1270083). Changes for jline3: * Update to upstream version 3.30.15 * fix: guard regex matching against catastrophic backtracking (ReDoS) (#2018, backport of #2012): * Adds SafeRegex utility with TimeoutCharSequence to enforce wall-clock deadlines during regex matching * Fixes 8 locations across terminal, reader, and builtins where user- controlled input could trigger catastrophic backtracking * Addresses GHSA-r2xf-8xr9-62gw, GHSA-2v9w-34q6-wpqx, GHSA-ph9c-7hw9-vhhw, GHSA-5q95-hrpc-m3w3

References

* bsc#1269021

* bsc#1270083

Cross-

* CVE-2026-56740

* CVE-2026-56741

CVSS scores:

* CVE-2026-56740 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-56740 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-56741 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-56741 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* SUSE Linux Enterprise Server 16.0

* SUSE Linux Enterprise Server for SAP applications 16.0

An update that solves two vulnerabilities can now be installed.

##

* https://www.suse.com/security/cve/CVE-2026-56740.html

* https://www.suse.com/security/cve/CVE-2026-56741.html

* https://bugzilla.suse.com/show_bug.cgi?id=1269021

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22856-1
Release Date: 2026-07-22T16:48:17Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.