Bug 2489141 (CVE-2026-8484)

Summary: CVE-2026-8484 jansi: org.fusesource.jansi/jansi: Jansi: Heap buffer overflow leads to Denial of Service
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, abrianik, ahughes, ant, anujha, aschwart, asoldano, aszczucz, avibelli, bbaranow, bgeorges, bmaxwell, boliveir, bstansbe, cescoffi, chfoley, cmah, dandread, dkreling, dlofthou, drichtar, eaguilar, ebaron, ewittman, fferrari, fmariani, fmongiar, ggrzybek, gmalinko, gsmet, gtanzill, istudens, ivassile, iweiss, janstey, jbuscemi, jmartisk, jmatsuok, jnethert, jraez, jtolenti, jwon, khosford, lthon, manderse, mcarlett, mosmerov, mposolda, msvehla, mtorre, nipatil, nwallace, olubyans, pantinor, parichar, pberan, pesilva, pgallagh, pjindal, pmackay, probinso, rgodfrey, rguimara, rhel-process-autobot, rjohnson, rkubis, rmartinc, rruss, rstancel, rstepani, rsvoboda, sbiarozk, sdawley, ssilvert, sthorger, swoodman, tasato, tcunning, tfitzsim, thjenkin, tqvarnst, vdosoudi, vmuzikar, watson-tool-maintainers, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Jansi. A heap buffer overflow vulnerability exists in the Jansi Java Native Interface (JNI) 'ioctl()' wrapper. This is due to a lack of size verification for the argument array before the system call, which can lead to heap corruption. An attacker could exploit this to cause application crashes, resulting in a Denial of Service (DoS).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-06-16 12:01:18 UTC
A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS).
All versions are believed to be vulnerable. This project is unmaintained at the time of CVE assignment.