Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
## This update for jline3 fixes the following issues: * CVE-2026-56740: unauthenticated remote memory exhaustion via unbounded Telnet `NEW-ENVIRON` variables (bsc#1269021). * CVE-2026-56741: unauthenticated remote DoS via Unbounded Telnet NAWS Terminal Geometry (bsc#1270083). Changes for jline3: * Update to upstream version 3.30.15 * fix: guard regex matching against catastrophic backtracking (ReDoS) (#2018, backport of #2012): * Adds SafeRegex utility with TimeoutCharSequence to enforce wall-clock deadlines during regex matching * Fixes 8 locations across terminal, reader, and builtins where user- controlled input could trigger catastrophic backtracking * Addresses GHSA-r2xf-8xr9-62gw, GHSA-2v9w-34q6-wpqx, GHSA-ph9c-7hw9-vhhw, GHSA-5q95-hrpc-m3w3
* bsc#1269021
* bsc#1270083
Cross-
* CVE-2026-56740
* CVE-2026-56741
CVSS scores:
* CVE-2026-56740 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56740 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56741 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56741 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* SUSE Linux Enterprise Server 16.0
* SUSE Linux Enterprise Server for SAP applications 16.0
An update that solves two vulnerabilities can now be installed.
##
* https://www.suse.com/security/cve/CVE-2026-56740.html
* https://www.suse.com/security/cve/CVE-2026-56741.html
* https://bugzilla.suse.com/show_bug.cgi?id=1269021
Get the latest Linux and open source security news straight to your inbox.