shield
Security update for jq
SUSE-SLE-Micro-6.0-788
This update for jq fixes the following issues Security issues fixed: - CVE-2025-9403: reacheable assertion in `run_jq_tests` can lead to program termination when processing malformed JSON input containing invalid Unicode escape sequences (bsc#1248600). - CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044). - CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to excessive resource consumption when processing crafted JSON input (bsc#1262069). - CVE-2026-33948: improper handling of buffer sizes via `strlen()` instead of `fgets()` in CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043). - CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when evaluating untrusted jq filters against a release build (bsc#1262070). - CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an out-of-bounds read when processing malformed JSON (bsc#1262071). - CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre-computation of key collisions and can lead to a denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072). Other updates and bugfixes: - spec: add `--enable-pthread-tls` to configure invocation.
-
Release DateJul 8 2026
-
ReferencesBugzilla: 1248600, 1262043, 1262044, 1262069, 1262070, 1262071, 1262072
CVEs: CVE-2025-9403, CVE-2026-32316, CVE-2026-33947, CVE-2026-33948, CVE-2026-39956, CVE-2026-39979, CVE-2026-40164 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Micro 6.0 x86_64
-
Packages
SUSE Linux Micro 6.0 aarch64
-
Packages
SUSE Linux Micro 6.0 s390x
-
Packages