SUSE-SU-2026:4394-1: important: Security update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformat-xml, jackson-dataformats-binary, jackson-modules-base

SLE-UPDATES null at suse.de
Tue Sep 29 17:19:50 UTC 2026


# Security update for jackson-annotations, jackson-bom, jackson-core, jackson-
databind, jackson-dataformat-xml, jackson-dataformats-binary, jackson-modules-
base

Announcement ID: SUSE-SU-2026:4394-1  
Release Date: 2026-09-29T11:53:07Z  
Rating: important  
References:

  * bsc#1273856
  * bsc#1273857
  * bsc#1277883
  * bsc#1278008
  * bsc#1280125
  * bsc#1282491
  * bsc#1282492
  * bsc#1282505
  * bsc#1282639
  * bsc#1282640
  * bsc#1282641
  * bsc#1282645

  
Cross-References:

  * CVE-2026-18401
  * CVE-2026-19032
  * CVE-2026-68494
  * CVE-2026-68495
  * CVE-2026-68496
  * CVE-2026-68497
  * CVE-2026-68498
  * CVE-2026-83557
  * CVE-2026-89407
  * CVE-2026-89425
  * CVE-2026-91776
  * CVE-2026-91777

  
CVSS scores:

  * CVE-2026-18401 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-18401 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-18401 ( NVD ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-19032 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-19032 ( SUSE ):  4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
  * CVE-2026-19032 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-68494 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-68494 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-68494 ( NVD ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-68495 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-68496 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-68497 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-68497 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-68497 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-68498 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-83557 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-83557 ( SUSE ):  5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-83557 ( NVD ):  5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-89407 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-89407 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-89425 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-89425 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-89425 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-91776 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-91776 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-91776 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-91777 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-91777 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-91777 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

  
Affected Products:

  * Basesystem Module 15-SP7
  * Development Tools Module 15-SP7
  * SUSE Linux Enterprise Desktop 15 SP7
  * SUSE Linux Enterprise High Performance Computing 15 SP4
  * SUSE Linux Enterprise High Performance Computing 15 SP5
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
  * SUSE Linux Enterprise Real Time 15 SP7
  * SUSE Linux Enterprise Server 15 SP4
  * SUSE Linux Enterprise Server 15 SP4 LTSS
  * SUSE Linux Enterprise Server 15 SP5
  * SUSE Linux Enterprise Server 15 SP5 LTSS
  * SUSE Linux Enterprise Server 15 SP6
  * SUSE Linux Enterprise Server 15 SP6 LTSS
  * SUSE Linux Enterprise Server 15 SP7
  * SUSE Linux Enterprise Server for SAP Applications 15 SP4
  * SUSE Linux Enterprise Server for SAP Applications 15 SP5
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6
  * SUSE Linux Enterprise Server for SAP Applications 15 SP7

  
  
An update that solves 12 vulnerabilities can now be installed.

## Description:

This update for jackson-annotations, jackson-bom, jackson-core, jackson-
databind, jackson-dataformat-xml, jackson-dataformats-binary, jackson-modules-
base fixes the following issues:

  * CVE-2026-18401: Number Length Constraint Bypass in Async Parser Can Lead to
    Potential Processing Time Issues (bsc#1273856).
  * CVE-2026-68494: Async parser maxNumberLength bypass via chunked digit
    accumulation (bsc#1273857).
  * CVE-2026-68495: Ensure maxNameLength limit enforced for CBOR parser
    (bsc#1282639).
  * CVE-2026-68496: Ensure maxNameLength limit enforced for Smile parser
    (bsc#1282640).
  * CVE-2026-68498: Enforce maxNameLength incrementally in ReaderBasedJsonParser
    (bsc#1282641).
  * CVE-2026-89407: Optimize NumberInput.looksLikeValidNumber (bsc#1282645).
  * CVE-2026-89425: `UTF8DataInputJsonParser._reportInvalidToken()`lacks
    `maxErrorTokenLength` limit, which allows for unbounded `StringBuilder`
    growth and can lead to a DoS when malformed tokens are processed
    (bsc#1282505).

Changes for jackson-annotations:

  * Update to 2.18.11

Changes for jackson-bom:

  * Update to 2.18.11

Changes for jackson-core:

  * Update to 2.18.11
  * # 1649: Optimize NumberInput.looksLikeValidNumber (bsc#1282645,

CVE-2026-89407)

  * # 1698: UTF8DataInputJsonParser does not honor

maxErrorTokenLength when reporting an unrecognized token (bsc#1282505,
CVE-2026-89425)

  * # 1642: Fix maxDocumentLength bypass in async parser

single-feedInput() case [GHSA-2c4j-63jj-9fqr]

  * # 1643: Enforce maxNameLength incrementally in

ReaderBasedJsonParser (bsc#1282641, CVE-2026-68498) of async parser
(bsc#1273857, CVE-2026-68494) non-blocking (async) parser (bsc#1273856,
CVE-2026-18401)

Changes for jackson-databind:

  * Update to 2.18.11
  * # 6185: Bracket unresolved IPv6 host name in InetSocketAddress

serialization

  * # 6203: Prevent unbounded growth of type id cache in

TypeDeserializer (bsc#1282491, CVE-2026-91776)

  * # 6204: Avoid quadratic forward-reference resolution in

Collection/Map deserializers (bsc#1282492, CVE-2026-91777)

  * # 6099: Resolve classes without initialization in

TypeFactory.findClass()

  * # 6116: Reject non-ASCII digits in InetAddress literal validation

  * # 6127: Add StreamReadConstraints number len constraint to

javax.xml.datatype.XMLGregorianCalendar and javax.xml.datatype.Duration
(bsc#1280125, CVE-2026-68497)

  * # 6129: Limit the supported URL schemes for java.nio.file.Path

deserialization (bsc#1277883, CVE-2026-19032)

  * # 6156: Add java.lang.Comparable in set of unsafe polymorphic

base types (bsc#1278008, CVE-2026-83557)

  * # 6165: Apply number length limits to BigDecimal/BigInteger/

/Double/Float Map keys

Changes for jackson-dataformat-xml:

  * Update to 2.18.11
  * Fix build to avoid past-JDK-8 bytecode generation
  * # 891: Enforce StreamReadConstraints.maxNestingDepth in

FromXmlParser

Changes for jackson-dataformats-binary:

  * Update to 2.18.11
  * # 783: (protobuf) Support StreamReadConstraints.maxDocumentLength

in ProtobufParser

  * # 785: (avro) Support StreamReadConstraints.maxDocumentLength and

maxTokenCount in Avro parser

  * # 803: (ion) Support StreamReadConstraints.maxNestingDepth in Ion

parser (partial fix for #358)

  * # 805: (ion) Support StreamReadConstraints.maxDocumentLength in

Ion parser (partial fix for #358)

  * # 725: (cbor) Ensure maxNameLength limit enforced for CBOR parser

(bsc#1282639, CVE-2026-68495)

  * # 726: (smile) Ensure maxNameLength limit enforced for Smile

parser (bsc#1282640, CVE-2026-68496)

  * # 727: (cbor) CBORParser.nextFieldName(SerializableString)

confuses 5-bit length marker 23 with 24 ("1-byte length suffix follows")

  * # 728: (cbor) CBORParser.nextFieldName(SerializableString)

consumes Object entry slot twice on fast-path miss, truncating definite-length
Objects

  * # 733: (cbor) Long `String`s not added to "stringref" reference

table, breaking following references

  * # 735: (cbor) "stringref" property-name paths pass 5-bit length

marker instead of actual length to shouldReferenceString()

  * # 736: (cbor) Long Object property names added to "stringref"

reference table twice

Changes for jackson-modules-base:

  * Update to 2.18.11

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server for SAP Applications 15 SP4  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4394

  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4394

  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4394

  * SUSE Linux Enterprise Server for SAP Applications 15 SP5  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4394

  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4394

  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4394

  * SUSE Linux Enterprise Server for SAP Applications 15 SP6  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4394

  * SUSE Linux Enterprise Server 15 SP4 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4394

  * Basesystem Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4394

  * Development Tools Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-4394

  * SUSE Linux Enterprise Server 15 SP5 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4394

  * SUSE Linux Enterprise Server 15 SP6 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4394

## Package List:

  * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
    * jackson-core-2.18.11-150200.3.30.1
    * jackson-annotations-2.18.11-150200.3.28.1
    * jackson-dataformat-cbor-2.18.11-150200.3.29.1
    * jackson-dataformat-xml-2.18.11-150200.5.8.1
    * jackson-databind-2.18.11-150200.3.36.1
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
    * jackson-core-2.18.11-150200.3.30.1
    * jackson-annotations-2.18.11-150200.3.28.1
    * jackson-dataformat-cbor-2.18.11-150200.3.29.1
    * jackson-dataformat-xml-2.18.11-150200.5.8.1
    * jackson-databind-2.18.11-150200.3.36.1
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
    * jackson-core-2.18.11-150200.3.30.1
    * jackson-annotations-2.18.11-150200.3.28.1
    * jackson-dataformat-cbor-2.18.11-150200.3.29.1
    * jackson-dataformat-xml-2.18.11-150200.5.8.1
    * jackson-databind-2.18.11-150200.3.36.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
    * jackson-core-2.18.11-150200.3.30.1
    * jackson-annotations-2.18.11-150200.3.28.1
    * jackson-dataformat-cbor-2.18.11-150200.3.29.1
    * jackson-dataformat-xml-2.18.11-150200.5.8.1
    * jackson-databind-2.18.11-150200.3.36.1
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
    * jackson-core-2.18.11-150200.3.30.1
    * jackson-annotations-2.18.11-150200.3.28.1
    * jackson-dataformat-cbor-2.18.11-150200.3.29.1
    * jackson-dataformat-xml-2.18.11-150200.5.8.1
    * jackson-databind-2.18.11-150200.3.36.1
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
    * jackson-core-2.18.11-150200.3.30.1
    * jackson-annotations-2.18.11-150200.3.28.1
    * jackson-dataformat-cbor-2.18.11-150200.3.29.1
    * jackson-dataformat-xml-2.18.11-150200.5.8.1
    * jackson-databind-2.18.11-150200.3.36.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
    * jackson-core-2.18.11-150200.3.30.1
    * jackson-annotations-2.18.11-150200.3.28.1
    * jackson-dataformat-cbor-2.18.11-150200.3.29.1
    * jackson-dataformat-xml-2.18.11-150200.5.8.1
    * jackson-databind-2.18.11-150200.3.36.1
  * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
    * jackson-core-2.18.11-150200.3.30.1
    * jackson-annotations-2.18.11-150200.3.28.1
    * jackson-dataformat-cbor-2.18.11-150200.3.29.1
    * jackson-dataformat-xml-2.18.11-150200.5.8.1
    * jackson-databind-2.18.11-150200.3.36.1
  * Basesystem Module 15-SP7 (noarch)
    * jackson-core-2.18.11-150200.3.30.1
    * jackson-databind-2.18.11-150200.3.36.1
    * jackson-annotations-2.18.11-150200.3.28.1
    * jackson-dataformat-xml-2.18.11-150200.5.8.1
  * Development Tools Module 15-SP7 (noarch)
    * jackson-dataformat-cbor-2.18.11-150200.3.29.1
  * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
    * jackson-core-2.18.11-150200.3.30.1
    * jackson-annotations-2.18.11-150200.3.28.1
    * jackson-dataformat-cbor-2.18.11-150200.3.29.1
    * jackson-dataformat-xml-2.18.11-150200.5.8.1
    * jackson-databind-2.18.11-150200.3.36.1
  * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
    * jackson-core-2.18.11-150200.3.30.1
    * jackson-annotations-2.18.11-150200.3.28.1
    * jackson-dataformat-cbor-2.18.11-150200.3.29.1
    * jackson-dataformat-xml-2.18.11-150200.5.8.1
    * jackson-databind-2.18.11-150200.3.36.1

## References:

  * https://www.suse.com/security/cve/CVE-2026-18401.html
  * https://www.suse.com/security/cve/CVE-2026-19032.html
  * https://www.suse.com/security/cve/CVE-2026-68494.html
  * https://www.suse.com/security/cve/CVE-2026-68495.html
  * https://www.suse.com/security/cve/CVE-2026-68496.html
  * https://www.suse.com/security/cve/CVE-2026-68497.html
  * https://www.suse.com/security/cve/CVE-2026-68498.html
  * https://www.suse.com/security/cve/CVE-2026-83557.html
  * https://www.suse.com/security/cve/CVE-2026-89407.html
  * https://www.suse.com/security/cve/CVE-2026-89425.html
  * https://www.suse.com/security/cve/CVE-2026-91776.html
  * https://www.suse.com/security/cve/CVE-2026-91777.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1273856
  * https://bugzilla.suse.com/show_bug.cgi?id=1273857
  * https://bugzilla.suse.com/show_bug.cgi?id=1277883
  * https://bugzilla.suse.com/show_bug.cgi?id=1278008
  * https://bugzilla.suse.com/show_bug.cgi?id=1280125
  * https://bugzilla.suse.com/show_bug.cgi?id=1282491
  * https://bugzilla.suse.com/show_bug.cgi?id=1282492
  * https://bugzilla.suse.com/show_bug.cgi?id=1282505
  * https://bugzilla.suse.com/show_bug.cgi?id=1282639
  * https://bugzilla.suse.com/show_bug.cgi?id=1282640
  * https://bugzilla.suse.com/show_bug.cgi?id=1282641
  * https://bugzilla.suse.com/show_bug.cgi?id=1282645

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260929/f1fe7f0c/attachment-0001.htm>


More information about the sle-updates mailing list