Security update for jq
This update for jq fixes the following issues: - CVE-2025-48060: improper handling of string data in `jv_string_empty` can lead to heap buffer overflow and a crash when processing crafted input (bsc#1244116). - CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044). - CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to excessive resource consumption when processing crafted JSON input (bsc#1262069). - CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when evaluating untrusted jq filters against a release build (bsc#1262070). - CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an out-of-bounds read when processing malformed JSON (bsc#1262071). - CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre-computation of key collisions and can lead to a denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072). - CVE-2026-40612: recursion into nested arrays/objects with no depth limit in `jv_contains` can lead to a C stack exhaustion when processing crafted input (bsc#1265060). - CVE-2026-41256: truncation of top-level jq programs loaded with `-f` and can lead to the execution of unintended programs (bsc#1265061). - CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS when processing jq bytecode (bsc#1265062). - CVE-2026-43894: signed integer overflow in the `decNumberFromString` `D2U()` macro can lead to an out-of-bounds memory write when processing large number literals (bsc#1265070). - CVE-2026-33948: improper handling of buffer sizes via `strlen()` instead of `fgets()` in CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043).
Security update for jq
Description
This update for jq fixes the following issues: - CVE-2025-48060: improper handling of string data in `jv_string_empty` can lead to heap buffer overflow and a crash when processing crafted input (bsc#1244116). - CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044). - CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to excessive resource consumption when processing crafted JSON input (bsc#1262069). - CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when evaluating untrusted jq filters against a release build (bsc#1262070). - CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an out-of-bounds read when processing malformed JSON (bsc#1262071). - CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre-computation of key collisions and can lead to a denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072). - CVE-2026-40612: recursion into nested arrays/objects with no depth limit in `jv_contains` can lead to a C stack exhaustion when processing crafted input (bsc#1265060). - CVE-2026-41256: truncation of top-level jq programs loaded with `-f` and can lead to the execution of unintended programs (bsc#1265061). - CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS when processing jq bytecode (bsc#1265062). - CVE-2026-43894: signed integer overflow in the `decNumberFromString` `D2U()` macro can lead to an out-of-bounds memory write when processing large number literals (bsc#1265070). - CVE-2026-33948: improper handling of buffer sizes via `strlen()` instead of `fgets()` in CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043).
Affected software
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- openSUSE-SU-2026:21248-1
- Cve Count
- 11
- Additional Cves
- ["CVE-2026-32316","CVE-2026-33947","CVE-2026-33948","CVE-2026-39956","CVE-2026-39979","CVE-2026-40164","CVE-2026-40612","CVE-2026-41256","CVE-2026-41257","CVE-2026-43894"]
Threat ID: 6aab496f55bf5e2cf5990e03
Added to database: 09/17/2026, 01:59:11 UTC
Last updated: 09/17/2026, 01:59:11 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.