Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-8484

Опубликовано: 16 июн. 2026
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS). All versions are believed to be vulnerable. This project is unmaintained at the time of CVE assignment.

A flaw was found in Jansi. A heap buffer overflow vulnerability exists in the Jansi Java Native Interface (JNI) 'ioctl()' wrapper. This is due to a lack of size verification for the argument array before the system call, which can lead to heap corruption. An attacker could exploit this to cause application crashes, resulting in a Denial of Service (DoS).

Отчет

This Moderate vulnerability in Jansi's JNI ioctl() wrapper can lead to a denial of service due to a heap buffer overflow. Exploitation requires local access and user interaction, as the flaw stems from insufficient size verification of the argument array before a system call, potentially causing application instability. The unmaintained status of the Jansi project increases the risk associated with this flaw.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4jansiFix deferred
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Out of support scope
Migration Toolkit for Applications 8mta/mta-cli-rhel9Fix deferred
Migration Toolkit for Applications 8mta/mta-java-external-provider-rhel9Fix deferred
OpenShift Developer Tools and ServicesjenkinsOut of support scope
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Out of support scope
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Out of support scope
Red Hat build of Apache Camel 4 for Quarkus 3jansiFix deferred
Red Hat build of Apache Camel for Spring Boot 4jansi.dllFix deferred
Red Hat build of Apache Camel - HawtIO 4jansiFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1284
https://bugzilla.redhat.com/show_bug.cgi?id=2489141jansi: org.fusesource.jansi/jansi: Jansi: Heap buffer overflow leads to Denial of Service

EPSS

Процентиль: 4%
0.0014
Низкий

5 Medium

CVSS3

Связанные уязвимости

ubuntu
около 2 месяцев назад

A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS). All versions are believed to be vulnerable. This project is unmaintained at the time of CVE assignment.

nvd
около 2 месяцев назад

A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS). All versions are believed to be vulnerable. This project is unmaintained at the time of CVE assignment.

debian
около 2 месяцев назад

A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" ...

github
около 2 месяцев назад

A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS). All versions are believed to be vulnerable. This project is unmaintained at the time of CVE assignment.

EPSS

Процентиль: 4%
0.0014
Низкий

5 Medium

CVSS3