Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56741

Опубликовано: 17 июл. 2026
Источник: redhat
CVSS3: 7.5

Описание

JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.

A flaw was found in the JLine3 Telnet server's remote-telnet module. An unauthenticated remote attacker can exploit this vulnerability by repeatedly sending large terminal dimension values through the Telnet Negotiate About Window Size (NAWS) option. This action triggers continuous, resource-intensive rendering processes, leading to CPU exhaustion and a denial of service (DoS) for the server.

Отчет

This is a denial of service vulnerability in the JLine3 Telnet server module. An unauthenticated remote attacker can exploit this flaw by sending specially crafted Telnet NAWS options, leading to continuous, expensive rendering work and subsequent CPU exhaustion on the server. This can disrupt services that embed the JLine3 remote-telnet module and expose its Telnet server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7jline-remote-telnetNot affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-spark-operator-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cpu-torch210-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cpu-torch291-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cuda130-torch210-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cuda130-torch291-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-rocm64-torch291-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th-torch-cpu-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th-torch-cuda-py312-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2501964org.jline/jline-remote-telnet: JLine3 Telnet server: Denial of Service via uncontrolled terminal dimensions

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.

CVSS3: 7.5
nvd
2 месяца назад

JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.

CVSS3: 7.5
debian
2 месяца назад

JLine is a Java library for handling console input. Prior to 3.30.14, ...

CVSS3: 7.5
github
3 месяца назад

JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry

suse-cvrf
2 месяца назад

Security update for jline3

7.5 High

CVSS3