CVE-2026-8484

NameCVE-2026-8484
DescriptionA heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS). All versions are believed to be vulnerable. This project is unmaintained at the time of CVE assignment.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1142997, 1142998

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
jansi (PTS)bullseye1.18-1fixed
bookworm2.4.0-2vulnerable
trixie2.4.1-2vulnerable
forky, sid2.4.2-1vulnerable
jansi-native (PTS)bookworm, bullseye1.8-1vulnerable
forky, sid, trixie1.8-2vulnerable
jansi1 (PTS)bookworm1.18-3fixed
trixie1.18-3.1fixed
forky, sid1.18-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
jansisourcebullseye(not affected)
jansisource(unstable)(unfixed)1142997
jansi-nativesource(unstable)(unfixed)1142998
jansi1source(unstable)(not affected)

Notes

[trixie] - jansi <no-dsa> (Minor issue)
[bookworm] - jansi <postponed> (Minor issue)
[bullseye] - jansi <not-affected> (jansi 1.x ships no native code; the vulnerable JNI ioctl is in jansi-native)
- jansi1 <not-affected> (Vulnerable code for JNI ioctl() in src:jansi-native)
[trixie] - jansi-native <no-dsa> (Minor issue)
[bookworm] - jansi-native <postponed> (Minor issue)
[bullseye] - jansi-native <postponed> (Minor issue)
https://cert.pl/en/posts/2026/06/CVE-2026-8484/
https://github.com/fusesource/jansi/issues/319

Search for package or bug name: Reporting problems