SUSE-SU-2026:23989-1: moderate: Security update for jline3

SLE-SECURITY-UPDATES null at suse.de
Mon Oct 5 08:35:38 UTC 2026


# Security update for jline3

Announcement ID: SUSE-SU-2026:23989-1  
Release Date: 2026-10-01T12:14:32Z  
Rating: moderate  
References:

  
Affected Products:

  * SUSE Linux Enterprise Server 16.0
  * SUSE Linux Enterprise Server for SAP applications 16.0

  
  
An update that can now be installed.

## Description:

This update for jline3 fixes the following issue:

Update to upstream version 3.30.17:

  * Security Fixes
  * Native Stack Buffer Overflow in Public INPUT_RECORD.memmove JNI Method
    (Windows) (GHSA-6r3w-6jpj-x5w6)
  * Authenticated SSH Shell Channel Resource Leak via Null or Non-Numeric PTY
    Dimensions (GHSA-7h86-pjwh-gpqj)
  * Authenticated SSH DoS via Unbounded Window-Change Terminal Geometry
    (GHSA-m935-wqpj-pvp3)
  * TCP Socket File Descriptor Leak When Maximum Connections Reached
    (GHSA-c87g-867h-cqr6)
  * Bug Fixes
  * strip control characters from file names in posix builtins
  * bound !# history expansion to prevent exponential blowup
  * verify server host keys in the ssh client builtin
  * address remaining security vulnerabilities reported by AFINE/CERT.PL
  * backport security fixes from master
  * backport security fixes to 3.x (path traversal + DSR plain text)
  * strip control characters from ssh banner and prompts
  * Dependency updates
  * bump com.diffplug.spotless:spotless-maven-plugin from 3.8.0 to 3.10.2
  * bump slf4j.version from 2.0.18 to 2.0.19
  * bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.6 to 3.6.0
  * bump org.apache.maven.plugins:maven-compiler-plugin from 3.15.0 to 3.16.0
  * bump org.apache.felix:maven-bundle-plugin from 6.0.2 to 6.1.2
  * bump actions/setup-java from 5 to 6.0.0
  * bump org.graalvm.sdk:graal-sdk from 25.1.3 to 25.3.4.1
  * bump com.mycila:license-maven-plugin from 5.0.0 to 5.1.2
  * bump org.easymock:easymock from 5.6.0 to 5.7.0
  * bump com.google.jimfs:jimfs from 1.3.1 to 1.3.2
  * bump org.apache.maven.wrapper:maven-wrapper from 3.3.2 to 3.3.4
  * bump org.apache.maven:apache-maven from 4.0.0-rc-3 to 4.0.0-rc-6
  * bump eu.maveniverse.maven.njord:extension3 from 0.9.9 to 0.9.10
  * bump com.palantir.javaformat:palantir-java-format from 2.96.0 to 2.97.0
  * bump release-drafter/release-drafter from 7.6.0 to 7.7.0
  * bump groovy.version from 4.0.32 to 4.0.33
  * bump release-drafter/release-drafter from 7 to 7.6.0
  * bump org.apache.maven.plugins:maven-jar-plugin from 3.5.0 to 3.5.1
  * Update to upstream version 3.30.16
  * bugfix release with security hardening, SSH agent forwarding fix, and
    terminal compatibility improvements.
  * Breaking Changes
  * SSH agent forwarding is no longer enabled by default; pass -A to explicitly
    request it
  * reject overlong hex components in OSC color responses
  * strip OSC and other escape sequences in ansiAppend
  * search multiple lib paths for versioned libutil.so
  * use Path.resolve instead of URI.resolve in cat and sort to prevent SSRF
  * check closed flag in PtyInputStream to prevent hang on empty input
  * confine ConfigurationPath lookups to the config directory
  * disable Read File command in nano restricted mode
  * drain buffered data before EOF in NonBlockingPumpInputStream
  * look up openpty in libc.so.6 for glibc 2.34+
  * guard styleMatches and highlighter rules against ReDoS
  * backport telnet DoS mitigations (GHSA-47qp, GHSA-2r2c)
  * propagate EOF in PtyInputStream to avoid infinite loop
  * bump org.apache.ivy:ivy from 2.5.3 to 2.6.0
  * bump actions/setup-node from 6 to 7
  * bump com.palantir.javaformat:palantir-java-format from 2.94.0 to 2.96.0
  * bump sshd.version from 2.18.0 to 2.19.0
  * bump org.codehaus.gmavenplus:gmavenplus-plugin from 5.0.0 to 5.1.0
  * bump org.graalvm.sdk:graal-sdk from 25.0.3 to 25.1.3
  * bump com.diffplug.spotless:spotless-maven-plugin

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server for SAP applications 16.0  
    zypper in -t patch SUSE-SLES-16.0-1800

  * SUSE Linux Enterprise Server 16.0  
    zypper in -t patch SUSE-SLES-16.0-1800

## Package List:

  * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64)
    * jline3-3.30.17-160000.1.1
    * jline3-debugsource-3.30.17-160000.1.1
    * jline3-native-debuginfo-3.30.17-160000.1.1
    * jline3-native-3.30.17-160000.1.1
    * jline3-jansi-3.30.17-160000.1.1
  * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch)
    * jline3-terminal-jni-3.30.17-160000.1.1
    * jline3-terminal-jna-3.30.17-160000.1.1
    * jline3-terminal-3.30.17-160000.1.1
    * jline3-reader-3.30.17-160000.1.1
    * jline3-console-ui-3.30.17-160000.1.1
    * jline3-console-3.30.17-160000.1.1
    * jline3-curses-3.30.17-160000.1.1
    * jline3-javadoc-3.30.17-160000.1.1
    * jline3-jansi-core-3.30.17-160000.1.1
    * jline3-builtins-3.30.17-160000.1.1
    * jline3-style-3.30.17-160000.1.1
    * jline3-terminal-jansi-3.30.17-160000.1.1
    * jline3-remote-telnet-3.30.17-160000.1.1
  * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64)
    * jline3-3.30.17-160000.1.1
    * jline3-debugsource-3.30.17-160000.1.1
    * jline3-native-debuginfo-3.30.17-160000.1.1
    * jline3-native-3.30.17-160000.1.1
    * jline3-jansi-3.30.17-160000.1.1
  * SUSE Linux Enterprise Server 16.0 (noarch)
    * jline3-terminal-jni-3.30.17-160000.1.1
    * jline3-terminal-jna-3.30.17-160000.1.1
    * jline3-terminal-3.30.17-160000.1.1
    * jline3-reader-3.30.17-160000.1.1
    * jline3-console-ui-3.30.17-160000.1.1
    * jline3-console-3.30.17-160000.1.1
    * jline3-curses-3.30.17-160000.1.1
    * jline3-javadoc-3.30.17-160000.1.1
    * jline3-jansi-core-3.30.17-160000.1.1
    * jline3-builtins-3.30.17-160000.1.1
    * jline3-style-3.30.17-160000.1.1
    * jline3-terminal-jansi-3.30.17-160000.1.1
    * jline3-remote-telnet-3.30.17-160000.1.1

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20261005/8970f55e/attachment.htm>


More information about the sle-security-updates mailing list