SUSE-SU-2026:23989-1: moderate: Security update for jline3
SLE-SECURITY-UPDATES
null at suse.de
Mon Oct 5 08:35:38 UTC 2026
# Security update for jline3
Announcement ID: SUSE-SU-2026:23989-1
Release Date: 2026-10-01T12:14:32Z
Rating: moderate
References:
Affected Products:
* SUSE Linux Enterprise Server 16.0
* SUSE Linux Enterprise Server for SAP applications 16.0
An update that can now be installed.
## Description:
This update for jline3 fixes the following issue:
Update to upstream version 3.30.17:
* Security Fixes
* Native Stack Buffer Overflow in Public INPUT_RECORD.memmove JNI Method
(Windows) (GHSA-6r3w-6jpj-x5w6)
* Authenticated SSH Shell Channel Resource Leak via Null or Non-Numeric PTY
Dimensions (GHSA-7h86-pjwh-gpqj)
* Authenticated SSH DoS via Unbounded Window-Change Terminal Geometry
(GHSA-m935-wqpj-pvp3)
* TCP Socket File Descriptor Leak When Maximum Connections Reached
(GHSA-c87g-867h-cqr6)
* Bug Fixes
* strip control characters from file names in posix builtins
* bound !# history expansion to prevent exponential blowup
* verify server host keys in the ssh client builtin
* address remaining security vulnerabilities reported by AFINE/CERT.PL
* backport security fixes from master
* backport security fixes to 3.x (path traversal + DSR plain text)
* strip control characters from ssh banner and prompts
* Dependency updates
* bump com.diffplug.spotless:spotless-maven-plugin from 3.8.0 to 3.10.2
* bump slf4j.version from 2.0.18 to 2.0.19
* bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.6 to 3.6.0
* bump org.apache.maven.plugins:maven-compiler-plugin from 3.15.0 to 3.16.0
* bump org.apache.felix:maven-bundle-plugin from 6.0.2 to 6.1.2
* bump actions/setup-java from 5 to 6.0.0
* bump org.graalvm.sdk:graal-sdk from 25.1.3 to 25.3.4.1
* bump com.mycila:license-maven-plugin from 5.0.0 to 5.1.2
* bump org.easymock:easymock from 5.6.0 to 5.7.0
* bump com.google.jimfs:jimfs from 1.3.1 to 1.3.2
* bump org.apache.maven.wrapper:maven-wrapper from 3.3.2 to 3.3.4
* bump org.apache.maven:apache-maven from 4.0.0-rc-3 to 4.0.0-rc-6
* bump eu.maveniverse.maven.njord:extension3 from 0.9.9 to 0.9.10
* bump com.palantir.javaformat:palantir-java-format from 2.96.0 to 2.97.0
* bump release-drafter/release-drafter from 7.6.0 to 7.7.0
* bump groovy.version from 4.0.32 to 4.0.33
* bump release-drafter/release-drafter from 7 to 7.6.0
* bump org.apache.maven.plugins:maven-jar-plugin from 3.5.0 to 3.5.1
* Update to upstream version 3.30.16
* bugfix release with security hardening, SSH agent forwarding fix, and
terminal compatibility improvements.
* Breaking Changes
* SSH agent forwarding is no longer enabled by default; pass -A to explicitly
request it
* reject overlong hex components in OSC color responses
* strip OSC and other escape sequences in ansiAppend
* search multiple lib paths for versioned libutil.so
* use Path.resolve instead of URI.resolve in cat and sort to prevent SSRF
* check closed flag in PtyInputStream to prevent hang on empty input
* confine ConfigurationPath lookups to the config directory
* disable Read File command in nano restricted mode
* drain buffered data before EOF in NonBlockingPumpInputStream
* look up openpty in libc.so.6 for glibc 2.34+
* guard styleMatches and highlighter rules against ReDoS
* backport telnet DoS mitigations (GHSA-47qp, GHSA-2r2c)
* propagate EOF in PtyInputStream to avoid infinite loop
* bump org.apache.ivy:ivy from 2.5.3 to 2.6.0
* bump actions/setup-node from 6 to 7
* bump com.palantir.javaformat:palantir-java-format from 2.94.0 to 2.96.0
* bump sshd.version from 2.18.0 to 2.19.0
* bump org.codehaus.gmavenplus:gmavenplus-plugin from 5.0.0 to 5.1.0
* bump org.graalvm.sdk:graal-sdk from 25.0.3 to 25.1.3
* bump com.diffplug.spotless:spotless-maven-plugin
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP applications 16.0
zypper in -t patch SUSE-SLES-16.0-1800
* SUSE Linux Enterprise Server 16.0
zypper in -t patch SUSE-SLES-16.0-1800
## Package List:
* SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64)
* jline3-3.30.17-160000.1.1
* jline3-debugsource-3.30.17-160000.1.1
* jline3-native-debuginfo-3.30.17-160000.1.1
* jline3-native-3.30.17-160000.1.1
* jline3-jansi-3.30.17-160000.1.1
* SUSE Linux Enterprise Server for SAP applications 16.0 (noarch)
* jline3-terminal-jni-3.30.17-160000.1.1
* jline3-terminal-jna-3.30.17-160000.1.1
* jline3-terminal-3.30.17-160000.1.1
* jline3-reader-3.30.17-160000.1.1
* jline3-console-ui-3.30.17-160000.1.1
* jline3-console-3.30.17-160000.1.1
* jline3-curses-3.30.17-160000.1.1
* jline3-javadoc-3.30.17-160000.1.1
* jline3-jansi-core-3.30.17-160000.1.1
* jline3-builtins-3.30.17-160000.1.1
* jline3-style-3.30.17-160000.1.1
* jline3-terminal-jansi-3.30.17-160000.1.1
* jline3-remote-telnet-3.30.17-160000.1.1
* SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64)
* jline3-3.30.17-160000.1.1
* jline3-debugsource-3.30.17-160000.1.1
* jline3-native-debuginfo-3.30.17-160000.1.1
* jline3-native-3.30.17-160000.1.1
* jline3-jansi-3.30.17-160000.1.1
* SUSE Linux Enterprise Server 16.0 (noarch)
* jline3-terminal-jni-3.30.17-160000.1.1
* jline3-terminal-jna-3.30.17-160000.1.1
* jline3-terminal-3.30.17-160000.1.1
* jline3-reader-3.30.17-160000.1.1
* jline3-console-ui-3.30.17-160000.1.1
* jline3-console-3.30.17-160000.1.1
* jline3-curses-3.30.17-160000.1.1
* jline3-javadoc-3.30.17-160000.1.1
* jline3-jansi-core-3.30.17-160000.1.1
* jline3-builtins-3.30.17-160000.1.1
* jline3-style-3.30.17-160000.1.1
* jline3-terminal-jansi-3.30.17-160000.1.1
* jline3-remote-telnet-3.30.17-160000.1.1
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20261005/8970f55e/attachment.htm>
More information about the sle-security-updates
mailing list