SUSE-SU-2026:4394-1: important: Security update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformat-xml, jackson-dataformats-binary, jackson-modules-base
SLE-SECURITY-UPDATES
null at suse.de
Tue Sep 29 17:20:07 UTC 2026
# Security update for jackson-annotations, jackson-bom, jackson-core, jackson-
databind, jackson-dataformat-xml, jackson-dataformats-binary, jackson-modules-
base
Announcement ID: SUSE-SU-2026:4394-1
Release Date: 2026-09-29T11:53:07Z
Rating: important
References:
* bsc#1273856
* bsc#1273857
* bsc#1277883
* bsc#1278008
* bsc#1280125
* bsc#1282491
* bsc#1282492
* bsc#1282505
* bsc#1282639
* bsc#1282640
* bsc#1282641
* bsc#1282645
Cross-References:
* CVE-2026-18401
* CVE-2026-19032
* CVE-2026-68494
* CVE-2026-68495
* CVE-2026-68496
* CVE-2026-68497
* CVE-2026-68498
* CVE-2026-83557
* CVE-2026-89407
* CVE-2026-89425
* CVE-2026-91776
* CVE-2026-91777
CVSS scores:
* CVE-2026-18401 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-18401 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-18401 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-19032 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-19032 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-19032 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-68494 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-68494 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-68494 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-68495 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-68496 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-68497 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-68497 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-68497 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-68498 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-83557 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-83557 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-83557 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-89407 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-89407 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-89425 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-89425 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-89425 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-91776 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-91776 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-91776 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-91777 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-91777 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-91777 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* Basesystem Module 15-SP7
* Development Tools Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves 12 vulnerabilities can now be installed.
## Description:
This update for jackson-annotations, jackson-bom, jackson-core, jackson-
databind, jackson-dataformat-xml, jackson-dataformats-binary, jackson-modules-
base fixes the following issues:
* CVE-2026-18401: Number Length Constraint Bypass in Async Parser Can Lead to
Potential Processing Time Issues (bsc#1273856).
* CVE-2026-68494: Async parser maxNumberLength bypass via chunked digit
accumulation (bsc#1273857).
* CVE-2026-68495: Ensure maxNameLength limit enforced for CBOR parser
(bsc#1282639).
* CVE-2026-68496: Ensure maxNameLength limit enforced for Smile parser
(bsc#1282640).
* CVE-2026-68498: Enforce maxNameLength incrementally in ReaderBasedJsonParser
(bsc#1282641).
* CVE-2026-89407: Optimize NumberInput.looksLikeValidNumber (bsc#1282645).
* CVE-2026-89425: `UTF8DataInputJsonParser._reportInvalidToken()`lacks
`maxErrorTokenLength` limit, which allows for unbounded `StringBuilder`
growth and can lead to a DoS when malformed tokens are processed
(bsc#1282505).
Changes for jackson-annotations:
* Update to 2.18.11
Changes for jackson-bom:
* Update to 2.18.11
Changes for jackson-core:
* Update to 2.18.11
* # 1649: Optimize NumberInput.looksLikeValidNumber (bsc#1282645,
CVE-2026-89407)
* # 1698: UTF8DataInputJsonParser does not honor
maxErrorTokenLength when reporting an unrecognized token (bsc#1282505,
CVE-2026-89425)
* # 1642: Fix maxDocumentLength bypass in async parser
single-feedInput() case [GHSA-2c4j-63jj-9fqr]
* # 1643: Enforce maxNameLength incrementally in
ReaderBasedJsonParser (bsc#1282641, CVE-2026-68498) of async parser
(bsc#1273857, CVE-2026-68494) non-blocking (async) parser (bsc#1273856,
CVE-2026-18401)
Changes for jackson-databind:
* Update to 2.18.11
* # 6185: Bracket unresolved IPv6 host name in InetSocketAddress
serialization
* # 6203: Prevent unbounded growth of type id cache in
TypeDeserializer (bsc#1282491, CVE-2026-91776)
* # 6204: Avoid quadratic forward-reference resolution in
Collection/Map deserializers (bsc#1282492, CVE-2026-91777)
* # 6099: Resolve classes without initialization in
TypeFactory.findClass()
* # 6116: Reject non-ASCII digits in InetAddress literal validation
* # 6127: Add StreamReadConstraints number len constraint to
javax.xml.datatype.XMLGregorianCalendar and javax.xml.datatype.Duration
(bsc#1280125, CVE-2026-68497)
* # 6129: Limit the supported URL schemes for java.nio.file.Path
deserialization (bsc#1277883, CVE-2026-19032)
* # 6156: Add java.lang.Comparable in set of unsafe polymorphic
base types (bsc#1278008, CVE-2026-83557)
* # 6165: Apply number length limits to BigDecimal/BigInteger/
/Double/Float Map keys
Changes for jackson-dataformat-xml:
* Update to 2.18.11
* Fix build to avoid past-JDK-8 bytecode generation
* # 891: Enforce StreamReadConstraints.maxNestingDepth in
FromXmlParser
Changes for jackson-dataformats-binary:
* Update to 2.18.11
* # 783: (protobuf) Support StreamReadConstraints.maxDocumentLength
in ProtobufParser
* # 785: (avro) Support StreamReadConstraints.maxDocumentLength and
maxTokenCount in Avro parser
* # 803: (ion) Support StreamReadConstraints.maxNestingDepth in Ion
parser (partial fix for #358)
* # 805: (ion) Support StreamReadConstraints.maxDocumentLength in
Ion parser (partial fix for #358)
* # 725: (cbor) Ensure maxNameLength limit enforced for CBOR parser
(bsc#1282639, CVE-2026-68495)
* # 726: (smile) Ensure maxNameLength limit enforced for Smile
parser (bsc#1282640, CVE-2026-68496)
* # 727: (cbor) CBORParser.nextFieldName(SerializableString)
confuses 5-bit length marker 23 with 24 ("1-byte length suffix follows")
* # 728: (cbor) CBORParser.nextFieldName(SerializableString)
consumes Object entry slot twice on fast-path miss, truncating definite-length
Objects
* # 733: (cbor) Long `String`s not added to "stringref" reference
table, breaking following references
* # 735: (cbor) "stringref" property-name paths pass 5-bit length
marker instead of actual length to shouldReferenceString()
* # 736: (cbor) Long Object property names added to "stringref"
reference table twice
Changes for jackson-modules-base:
* Update to 2.18.11
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4394
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4394
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4394
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4394
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4394
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4394
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4394
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4394
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4394
* Development Tools Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-4394
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4394
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4394
## Package List:
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
* jackson-core-2.18.11-150200.3.30.1
* jackson-annotations-2.18.11-150200.3.28.1
* jackson-dataformat-cbor-2.18.11-150200.3.29.1
* jackson-dataformat-xml-2.18.11-150200.5.8.1
* jackson-databind-2.18.11-150200.3.36.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* jackson-core-2.18.11-150200.3.30.1
* jackson-annotations-2.18.11-150200.3.28.1
* jackson-dataformat-cbor-2.18.11-150200.3.29.1
* jackson-dataformat-xml-2.18.11-150200.5.8.1
* jackson-databind-2.18.11-150200.3.36.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
* jackson-core-2.18.11-150200.3.30.1
* jackson-annotations-2.18.11-150200.3.28.1
* jackson-dataformat-cbor-2.18.11-150200.3.29.1
* jackson-dataformat-xml-2.18.11-150200.5.8.1
* jackson-databind-2.18.11-150200.3.36.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* jackson-core-2.18.11-150200.3.30.1
* jackson-annotations-2.18.11-150200.3.28.1
* jackson-dataformat-cbor-2.18.11-150200.3.29.1
* jackson-dataformat-xml-2.18.11-150200.5.8.1
* jackson-databind-2.18.11-150200.3.36.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* jackson-core-2.18.11-150200.3.30.1
* jackson-annotations-2.18.11-150200.3.28.1
* jackson-dataformat-cbor-2.18.11-150200.3.29.1
* jackson-dataformat-xml-2.18.11-150200.5.8.1
* jackson-databind-2.18.11-150200.3.36.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* jackson-core-2.18.11-150200.3.30.1
* jackson-annotations-2.18.11-150200.3.28.1
* jackson-dataformat-cbor-2.18.11-150200.3.29.1
* jackson-dataformat-xml-2.18.11-150200.5.8.1
* jackson-databind-2.18.11-150200.3.36.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* jackson-core-2.18.11-150200.3.30.1
* jackson-annotations-2.18.11-150200.3.28.1
* jackson-dataformat-cbor-2.18.11-150200.3.29.1
* jackson-dataformat-xml-2.18.11-150200.5.8.1
* jackson-databind-2.18.11-150200.3.36.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
* jackson-core-2.18.11-150200.3.30.1
* jackson-annotations-2.18.11-150200.3.28.1
* jackson-dataformat-cbor-2.18.11-150200.3.29.1
* jackson-dataformat-xml-2.18.11-150200.5.8.1
* jackson-databind-2.18.11-150200.3.36.1
* Basesystem Module 15-SP7 (noarch)
* jackson-core-2.18.11-150200.3.30.1
* jackson-databind-2.18.11-150200.3.36.1
* jackson-annotations-2.18.11-150200.3.28.1
* jackson-dataformat-xml-2.18.11-150200.5.8.1
* Development Tools Module 15-SP7 (noarch)
* jackson-dataformat-cbor-2.18.11-150200.3.29.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* jackson-core-2.18.11-150200.3.30.1
* jackson-annotations-2.18.11-150200.3.28.1
* jackson-dataformat-cbor-2.18.11-150200.3.29.1
* jackson-dataformat-xml-2.18.11-150200.5.8.1
* jackson-databind-2.18.11-150200.3.36.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* jackson-core-2.18.11-150200.3.30.1
* jackson-annotations-2.18.11-150200.3.28.1
* jackson-dataformat-cbor-2.18.11-150200.3.29.1
* jackson-dataformat-xml-2.18.11-150200.5.8.1
* jackson-databind-2.18.11-150200.3.36.1
## References:
* https://www.suse.com/security/cve/CVE-2026-18401.html
* https://www.suse.com/security/cve/CVE-2026-19032.html
* https://www.suse.com/security/cve/CVE-2026-68494.html
* https://www.suse.com/security/cve/CVE-2026-68495.html
* https://www.suse.com/security/cve/CVE-2026-68496.html
* https://www.suse.com/security/cve/CVE-2026-68497.html
* https://www.suse.com/security/cve/CVE-2026-68498.html
* https://www.suse.com/security/cve/CVE-2026-83557.html
* https://www.suse.com/security/cve/CVE-2026-89407.html
* https://www.suse.com/security/cve/CVE-2026-89425.html
* https://www.suse.com/security/cve/CVE-2026-91776.html
* https://www.suse.com/security/cve/CVE-2026-91777.html
* https://bugzilla.suse.com/show_bug.cgi?id=1273856
* https://bugzilla.suse.com/show_bug.cgi?id=1273857
* https://bugzilla.suse.com/show_bug.cgi?id=1277883
* https://bugzilla.suse.com/show_bug.cgi?id=1278008
* https://bugzilla.suse.com/show_bug.cgi?id=1280125
* https://bugzilla.suse.com/show_bug.cgi?id=1282491
* https://bugzilla.suse.com/show_bug.cgi?id=1282492
* https://bugzilla.suse.com/show_bug.cgi?id=1282505
* https://bugzilla.suse.com/show_bug.cgi?id=1282639
* https://bugzilla.suse.com/show_bug.cgi?id=1282640
* https://bugzilla.suse.com/show_bug.cgi?id=1282641
* https://bugzilla.suse.com/show_bug.cgi?id=1282645
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260929/25447943/attachment.htm>
More information about the sle-security-updates
mailing list