Executive brief
Jansi is a Java library used to format console output with ANSI escape sequences, commonly used in command-line applications. A flaw in how it handles system calls can allow a local attacker to cause the application to crash or behave unexpectedly. Because the project is currently unmaintained, no official fix is available, which may impact the stability of applications relying on this library for terminal interactions.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Jansi Java Native Interface (JNI) wrapper for the ioctl() system call. The vulnerability is caused by a lack of size verification for the argument array before it is passed to the underlying system call. An attacker who can influence the arguments passed to this wrapper can trigger heap corruption. This typically results in a Denial of Service (DoS) via application crash. The vulnerability affects all versions up to 2.4.3; however, the project is unmaintained, and no patch has been released.
Affected products
- FuseSource jansi All versions through 2.4.3
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory: NVD and CERT.PL published advisory