Skip to content

[GHSA-fh45-7f3j-r575] A heap buffer overflow vulnerability exists in the Jansi... - #10194

Open
levpachmanov wants to merge 1 commit into
levpachmanov/advisory-improvement-10194from
levpachmanov-GHSA-fh45-7f3j-r575
Open

levpachmanov wants to merge 1 commit into
levpachmanov/advisory-improvement-10194from
levpachmanov-GHSA-fh45-7f3j-r575

Conversation

@levpachmanov

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v4
  • Description
  • References
  • Source code location
  • Summary

Comments
This advisory currently lists no affected packages, so tools that match on GitHub advisories (including Dependabot) never flag Jansi. CERT Polska's advisory (https://cert.pl/en/posts/2026/06/CVE-2026-8484) states the issue affects Jansi through 2.4.3. That is the Maven artifact org.fusesource.jansi:jansi, and 2.4.3 is its last release (the project was deprecated in fusesource/jansi#312), so there is no patched version. The vulnerable code is the ioctl__IJ_3I JNI wrapper in src/main/native/jansi.c, unchanged in the 2.4.x releases.
Affected ranges were confirmed by inspecting the published jars: the ioctl(int, long, int[]) overload first appears in jansi-native 1.6 (bundled from jansi 1.12), and the Windows DLLs do not contain the wrapper.

@github-actions
github-actions Bot changed the base branch from main to levpachmanov/advisory-improvement-10194 October 6, 2026 17:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant