gpp_maybe
Security update for jq
SUSE-SL-Micro-6.2-1221
This update for jq fixes the following issues - CVE-2026-43896: unbounded recursion in jv_object_merge_recursive() can lead to C stack exhaustion and a process crash (bsc#1265075). - CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076). - CVE-2026-49839: fixed a bug where jq --rawfile can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds (bsc#1269220). - CVE-2026-54679: integer overflow in jvp_string_append can lead to a buffer overrun on 32-bit systems (bsc#1269390).
-
Release DateJul 13 2026
-
ReferencesBugzilla: 1265075, 1265076, 1269220, 1269390
CVEs: CVE-2026-43896, CVE-2026-44777, CVE-2026-49839, CVE-2026-54679 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Micro 6.2 ppc64le
-
Packages
SUSE Linux Micro 6.2 aarch64
-
Packages
SUSE Linux Micro 6.2 s390x
-
Packages
SUSE Linux Micro 6.2 x86_64
-
Packages