Linuxsecurity Debian Jackson-Core Vulnerability Poses DoS Risk
Article Content
- •A critical DoS vulnerability in Jackson-Core affects multiple Debian distributions.
- •Users must upgrade to specific versions to mitigate the risk of exploitation.
- •The vulnerability is tracked under CVE-2025, with fixes available for Bullseye, Bookworm, and Trixie.
A critical vulnerability in the Jackson-Core library has been identified, affecting multiple Debian distributions. The vulnerability, associated with CVE-2025, allows for potential Denial of Service (DoS) attacks. Affected packages include jackson-databind and jackson-dataformat-smile, which require upgrades to mitigate build failures. For Debian 11 (Bullseye), the fix is available in version 2.14.1-2~deb11u1, while Debian 12 (Bookworm) and Debian 13 (Trixie) have their respective fixes in versions 2.14.1-2~deb12u1 and 2.14.1-2~deb13u1. Users are strongly advised to upgrade their jackson-core packages to ensure system security. The vulnerability was highlighted in a recent advisory, emphasizing the urgency of the situation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…