Stack-based buffer overflow in jline3 - #VU148445

 

Stack-based buffer overflow in jline3 - #VU148445

Published: September 9, 2026


Vulnerability identifier: #VU148445
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary native code.

The vulnerability exists due to a stack-based buffer overflow in the public INPUT_RECORD.memmove JNI method when calling the method with an oversized size argument. A local user can invoke the method with a caller-controlled source address and oversized size argument to execute arbitrary native code.

The vulnerable native code is compiled exclusively for Windows targets.


Affected software

jline3

Remediation

Install security update from vendor's website.

jline3 - update to 4.4.3

External References

Related Security Bulletins