SB2026041453 - Anolis OS update for composer
Published: April 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper input validation (CVE-ID: CVE-2025-67746)
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper neutralization of terminal control sequences in terminal output handling when processing data from remote sources. A remote attacker can inject ANSI control characters to cause a denial of service.
The issue may also mangle terminal output and lead to user confusion.
Remediation
Install update from vendor's website.