Heap buffer overflow in Jansi
Published Jun 16, 2026
4.8
MEDIUMCVSS 4.0
EPSS 0.18%
Description
A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS). All versions are believed to be vulnerable. This project is unmaintained at the time of CVE assignment.
Affected products
-
- Version 0StatusaffectedConstraints<=2.4.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| FuseSource | Jansi | n/a |
|
No data.
No data.
Red Hat build of Quarkus 3.27.5
jansi
Fixed · RHSA-2026:53643
Red Hat build of Quarkus 3.33.3
jansi
Fixed · RHSA-2026:51653
Cryostat 4
jansi
Fix deferred
Exploit Intelligence
exploit-intelligence-tech-preview/vulnerability-analysis-rhel9
Out of support scope
Migration Toolkit for Applications 8
mta/mta-cli-rhel9
Fix deferred
Migration Toolkit for Applications 8
mta/mta-java-external-provider-rhel9
Fix deferred
OpenShift Developer Tools and Services
jenkins
Out of support scope
OpenShift Developer Tools and Services
ocp-tools-4/jenkins-rhel8
Out of support scope
OpenShift Developer Tools and Services
ocp-tools-4/jenkins-rhel9
Out of support scope
Red Hat Build of Keycloak
jansi
Fix deferred
Red Hat Build of Keycloak
rhbk-keycloak-rhel9/rhbk-keycloak-rhel9
Fix deferred
Red Hat Build of Keycloak
rhbk-openshift-rhel9/rhbk-openshift-rhel9
Fix deferred
Red Hat Data Grid 8
jansi
Out of support scope
Red Hat Enterprise Linux 10
jansi
Fix deferred
Red Hat Enterprise Linux 7
groovy
Fix deferred
Red Hat Enterprise Linux 7
jansi
Fix deferred
Red Hat Enterprise Linux 8
javapackages-tools:201801/jansi
Fix deferred
Red Hat Enterprise Linux 8
javapackages-tools:201801/jline
Fix deferred
Red Hat Enterprise Linux 8
javapackages-tools:201801/maven
Fix deferred
Red Hat Enterprise Linux 8
javapackages-tools:201801/maven-shared-utils
Fix deferred
Red Hat Enterprise Linux 8
javapackages-tools:201801/maven-surefire
Fix deferred
Red Hat Enterprise Linux 8
maven:3.8/jansi
Fix deferred
Red Hat Enterprise Linux 9
jansi
Fix deferred
Red Hat Enterprise Linux 9
maven
Fix deferred
Red Hat Enterprise Linux 9
maven-shared-utils
Fix deferred
Red Hat Enterprise Linux 9
maven:3.9/jansi
Fix deferred
Red Hat Enterprise Linux 9
maven:3.9/maven
Fix deferred
Red Hat Enterprise Linux 9
maven:3.9/maven-shared-utils
Fix deferred
Red Hat JBoss Enterprise Application Platform 7
eap74-els-openjdk11-openshift-rhel8/eap74-els-openjdk11-openshift-rhel8
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
eap74-els-openjdk17-openshift-rhel8/eap74-els-openjdk17-openshift-rhel8
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
eap74-els-openjdk8-openshift-rhel8/eap74-els-openjdk8-openshift-rhel8
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jansi
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7-eap74-els-openjdk17-openshift-rhel8/jboss-eap-7-eap74-els-openjdk17-openshift-rhel8
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7-eap74-els-openjdk8-openshift-rhel8/jboss-eap-7-eap74-els-openjdk8-openshift-rhel8
Out of support scope
Red Hat JBoss Enterprise Application Platform 8
jansi
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
jboss-eap-8-tech-preview-eap81-openjdk17-builder-openshift-rhel9/jboss-eap-8-tech-preview-eap81-openjdk17-builder-openshift-rhel9
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
jansi
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-trustyai-service-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/udi-rhel9
Fix deferred
Red Hat Single Sign-On 7
jansi
Out of support scope
Red Hat build of Apache Camel - HawtIO 4
jansi
Fix deferred
Red Hat build of Apache Camel 4 for Quarkus 3
jansi
Fix deferred
Red Hat build of Apache Camel for Spring Boot 4
jansi.dll
Fix deferred
Red Hat build of Apicurio Registry 3
jansi
Out of support scope
Red Hat build of OpenJDK Konflux Container Build
ubi10/openjdk-21
Fix deferred
Red Hat build of OpenJDK Konflux Container Build
ubi10/openjdk-25
Fix deferred
streams for Apache Kafka 2
jansi
Out of support scope
streams for Apache Kafka 3
jansi
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Quarkus 3.27.5 | jansi | Fixed | RHSA-2026:53643 |
| Red Hat build of Quarkus 3.33.3 | jansi | Fixed | RHSA-2026:51653 |
| Cryostat 4 | jansi | Fix deferred | n/a |
| Exploit Intelligence | exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 | Out of support scope | n/a |
| Migration Toolkit for Applications 8 | mta/mta-cli-rhel9 | Fix deferred | n/a |
| Migration Toolkit for Applications 8 | mta/mta-java-external-provider-rhel9 | Fix deferred | n/a |
| OpenShift Developer Tools and Services | jenkins | Out of support scope | n/a |
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Out of support scope | n/a |
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Out of support scope | n/a |
| Red Hat Build of Keycloak | jansi | Fix deferred | n/a |
| Red Hat Build of Keycloak | rhbk-keycloak-rhel9/rhbk-keycloak-rhel9 | Fix deferred | n/a |
| Red Hat Build of Keycloak | rhbk-openshift-rhel9/rhbk-openshift-rhel9 | Fix deferred | n/a |
| Red Hat Data Grid 8 | jansi | Out of support scope | n/a |
| Red Hat Enterprise Linux 10 | jansi | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | groovy | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | jansi | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | javapackages-tools:201801/jansi | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | javapackages-tools:201801/jline | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | javapackages-tools:201801/maven | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | javapackages-tools:201801/maven-shared-utils | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | javapackages-tools:201801/maven-surefire | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | maven:3.8/jansi | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | jansi | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | maven | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | maven-shared-utils | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | maven:3.9/jansi | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | maven:3.9/maven | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | maven:3.9/maven-shared-utils | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | eap74-els-openjdk11-openshift-rhel8/eap74-els-openjdk11-openshift-rhel8 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | eap74-els-openjdk17-openshift-rhel8/eap74-els-openjdk17-openshift-rhel8 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | eap74-els-openjdk8-openshift-rhel8/eap74-els-openjdk8-openshift-rhel8 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jansi | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7-eap74-els-openjdk17-openshift-rhel8/jboss-eap-7-eap74-els-openjdk17-openshift-rhel8 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7-eap74-els-openjdk8-openshift-rhel8/jboss-eap-7-eap74-els-openjdk8-openshift-rhel8 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | jansi | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | jboss-eap-8-tech-preview-eap81-openjdk17-builder-openshift-rhel9/jboss-eap-8-tech-preview-eap81-openjdk17-builder-openshift-rhel9 | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jansi | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-trustyai-service-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/udi-rhel9 | Fix deferred | n/a |
| Red Hat Single Sign-On 7 | jansi | Out of support scope | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | jansi | Fix deferred | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | jansi | Fix deferred | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | jansi.dll | Fix deferred | n/a |
| Red Hat build of Apicurio Registry 3 | jansi | Out of support scope | n/a |
| Red Hat build of OpenJDK Konflux Container Build | ubi10/openjdk-21 | Fix deferred | n/a |
| Red Hat build of OpenJDK Konflux Container Build | ubi10/openjdk-25 | Fix deferred | n/a |
| streams for Apache Kafka 2 | jansi | Out of support scope | n/a |
| streams for Apache Kafka 3 | jansi | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Moderate vulnerability in Jansi's JNI `ioctl()` wrapper can lead to a denial of service due to a heap buffer overflow. Exploitation requires local access and user interaction, as the flaw stems from insufficient size verification of the argument array before a system call, potentially causing application instability. The unmaintained status of the Jansi project increases the risk associated with this flaw.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-8484 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2489141 Issue Tracking
- https://cert.pl/en/posts/2026/06/CVE-2026-8484 third-party-advisory
- https://github.com/fusesource/jansi/tree/master product
- https://nvd.nist.gov/vuln/detail/CVE-2026-8484
- https://www.cve.org/CVERecord?id=CVE-2026-8484
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-8484 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2489141 | Issue Tracking | |
| https://cert.pl/en/posts/2026/06/CVE-2026-8484 | third-party-advisory | |
| https://github.com/fusesource/jansi/tree/master | product | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-8484 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-8484 |
Change history (0)
No recorded changes yet.