gpp_maybe Security update for jline3
SUSE-SLES-16.0-1334


This update for jline3 fixes the following issues: - CVE-2026-56740: unauthenticated remote memory exhaustion via unbounded Telnet `NEW-ENVIRON` variables (bsc#1269021). - CVE-2026-56741: unauthenticated remote DoS via Unbounded Telnet NAWS Terminal Geometry (bsc#1270083). Changes for jline3: - Update to upstream version 3.30.15 + fix: guard regex matching against catastrophic backtracking (ReDoS) (#2018, backport of #2012): * Adds SafeRegex utility with TimeoutCharSequence to enforce wall-clock deadlines during regex matching * Fixes 8 locations across terminal, reader, and builtins where user-controlled input could trigger catastrophic backtracking * Addresses GHSA-r2xf-8xr9-62gw, GHSA-2v9w-34q6-wpqx, GHSA-ph9c-7hw9-vhhw, GHSA-5q95-hrpc-m3w3 + fix: backport security hardening (#1986, #1995): * Create persisted history file with owner-only permissions * Use exclusive create for extracted native library temp files + fix: warn on insecure permissions when history file created concurrently


cloud_download Downloads

SUSE Linux Enterprise Server 16.0 aarch64
SUSE Linux Enterprise Server 16.0 ppc64le
SUSE Linux Enterprise Server 16.0 s390x
SUSE Linux Enterprise Server 16.0 x86_64
SUSE Linux Enterprise Server for SAP applications 16.0 ppc64le
SUSE Linux Enterprise Server for SAP applications 16.0 x86_64