Stack-based buffer overflow in jline3 - #VU148445
Published: September 9, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary native code.
The vulnerability exists due to a stack-based buffer overflow in the public INPUT_RECORD.memmove JNI method when calling the method with an oversized size argument. A local user can invoke the method with a caller-controlled source address and oversized size argument to execute arbitrary native code.
The vulnerable native code is compiled exclusively for Windows targets.