Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-54679

Опубликовано: 25 июн. 2026
Источник: debian
EPSS Низкий

Описание

jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun. This vulnerability is fixed in 1.8.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jqfixed1.8.2-1package

Примечания

  • https://github.com/jqlang/jq/security/advisories/GHSA-29gj-222p-j7vx

EPSS

Процентиль: 1%
0.00103
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 1 месяца назад

jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun. This vulnerability is fixed in 1.8.2.

CVSS3: 5.5
redhat
около 1 месяца назад

jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun. This vulnerability is fixed in 1.8.2.

CVSS3: 5.5
nvd
около 1 месяца назад

jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun. This vulnerability is fixed in 1.8.2.

msrc
около 1 месяца назад

jq: potential integer overflow in jvp_string_append

suse-cvrf
21 день назад

Security update for jq

EPSS

Процентиль: 1%
0.00103
Низкий