Red Hat Security Advisory: jq security update
Two security vulnerabilities have been identified in jq, a command-line JSON processor, affecting Red Hat Enterprise Linux 9.4 Extended Update Support and related products. The first is a signed integer overflow in the jvp_array_write function (CVE-2024-23337), and the second is a stack-buffer-overflow detected by AddressSanitizer in jq_fuzz_execute (CVE-2025-48060). Red Hat has issued a security advisory rating these issues as moderate severity and has released updated packages to address these vulnerabilities.
AI Analysis
Technical Summary
This advisory covers two vulnerabilities in jq, a lightweight JSON processor used in Red Hat Enterprise Linux 9.4 Extended Update Support and related distributions. CVE-2024-23337 is a signed integer overflow in the jvp_array_write function in jv.c, which could lead to unexpected behavior or memory corruption. CVE-2025-48060 is a stack-buffer-overflow detected by AddressSanitizer in the jq_fuzz_execute function (jv_string_vfmt), which could cause crashes or memory corruption. Red Hat has released updated jq packages (version 1.6-16.el9_4.1) for multiple architectures and variants to fix these issues.
Potential Impact
The vulnerabilities could lead to memory corruption or crashes when processing specially crafted JSON data with jq. This may affect system stability or security depending on how jq is used. The Red Hat advisory rates the impact as moderate. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released updated jq packages for Red Hat Enterprise Linux 9.4 Extended Update Support and related products. Users should apply these updates promptly to remediate the vulnerabilities. For detailed update instructions, refer to the Red Hat advisory at https://access.redhat.com/articles/11258. No other mitigation is indicated by the vendor advisory.
Red Hat Security Advisory: jq security update
Description
Two security vulnerabilities have been identified in jq, a command-line JSON processor, affecting Red Hat Enterprise Linux 9.4 Extended Update Support and related products. The first is a signed integer overflow in the jvp_array_write function (CVE-2024-23337), and the second is a stack-buffer-overflow detected by AddressSanitizer in jq_fuzz_execute (CVE-2025-48060). Red Hat has issued a security advisory rating these issues as moderate severity and has released updated packages to address these vulnerabilities.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers two vulnerabilities in jq, a lightweight JSON processor used in Red Hat Enterprise Linux 9.4 Extended Update Support and related distributions. CVE-2024-23337 is a signed integer overflow in the jvp_array_write function in jv.c, which could lead to unexpected behavior or memory corruption. CVE-2025-48060 is a stack-buffer-overflow detected by AddressSanitizer in the jq_fuzz_execute function (jv_string_vfmt), which could cause crashes or memory corruption. Red Hat has released updated jq packages (version 1.6-16.el9_4.1) for multiple architectures and variants to fix these issues.
Potential Impact
The vulnerabilities could lead to memory corruption or crashes when processing specially crafted JSON data with jq. This may affect system stability or security depending on how jq is used. The Red Hat advisory rates the impact as moderate. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released updated jq packages for Red Hat Enterprise Linux 9.4 Extended Update Support and related products. Users should apply these updates promptly to remediate the vulnerabilities. For detailed update instructions, refer to the Red Hat advisory at https://access.redhat.com/articles/11258. No other mitigation is indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:10613
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-48060"]
Threat ID: 6a1f4e89e29bf47b50082bf1
Added to database: 06/02/2026, 21:43:37 UTC
Last enriched: 08/21/2026, 16:16:02 UTC
Last updated: 09/10/2026, 19:36:47 UTC
Views: 69
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.