shield
Security update for jq
SUSE-SLE-Micro-5.5-2026-2983
This update for jq fixes the following issues: - CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044). - CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to excessive resource consumption when processing crafted JSON input (bsc#1262069). - CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when evaluating untrusted jq filters against a release build (bsc#1262070). - CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an out-of-bounds read when processing malformed JSON (bsc#1262071). - CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre-computation of key collisions and can lead to a denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072).
-
Release DateJul 14 2026
-
ReferencesBugzilla: 1262044, 1262069, 1262070, 1262071, 1262072
CVEs: CVE-2026-32316, CVE-2026-33947, CVE-2026-39956, CVE-2026-39979, CVE-2026-40164 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Micro 5.5 ppc64le
-
Packages
SUSE Linux Enterprise Micro 5.5 aarch64
-
Packages
SUSE Linux Enterprise Micro 5.5 s390x
-
Packages
SUSE Linux Enterprise Micro 5.5 x86_64
-
Packages