Debian Jackson-Core Vulnerability Poses DoS Risk

Debian Jackson-Core Vulnerability Poses DoS Risk

First seen 10 Jun 2026, 22:56 UTC Linuxsecurity 90% similarity 72.0

Article Content

Browse articles
ThreatCluster

A critical vulnerability in the Jackson-Core library has been identified, affecting multiple Debian distributions. The vulnerability, associated with CVE-2025, allows for potential Denial of Service (DoS) attacks. Affected packages include jackson-databind and jackson-dataformat-smile, which require upgrades to mitigate build failures. For Debian 11 (Bullseye), the fix is available in version 2.14.1-2~deb11u1, while Debian 12 (Bookworm) and Debian 13 (Trixie) have their respective fixes in versions 2.14.1-2~deb12u1 and 2.14.1-2~deb13u1. Users are strongly advised to upgrade their jackson-core packages to ensure system security. The vulnerability was highlighted in a recent advisory, emphasizing the urgency of the situation.

Key Points: • A critical DoS vulnerability in Jackson-Core affects multiple Debian distributions. • Users must upgrade to specific versions to mitigate the risk of exploitation. • The vulnerability is tracked under CVE-2025, with fixes available for Bullseye, Bookworm, and Trixie.

ThreatCluster AI

Timeline

2026-06-08
Debian Jackson-Core vulnerability advisory published
Linuxsecurity reported on the need to upgrade jackson-core packages due to build failures.
Linuxsecurity
2026-06-10
CVE-2025 identified as a DoS risk
The vulnerability in Jackson-Core was confirmed to allow Denial of Service attacks, prompting urgent upgrades.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story