Количество 8
Количество 8
BDU:2026-10392
Уязвимость утилиты для обработки JSON-файлов jq, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260707-73-0009
Уязвимость jq
CVE-2026-41257
jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.
CVE-2026-41257
jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.
CVE-2026-41257
jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.
CVE-2026-41257
jq: Signed-int overflow in `stack_reallocate` (jq VM stack)
CVE-2026-41257
jq is a command-line JSON processor. In 1.8.1 and earlier, the jq byte ...
openSUSE-SU-2026:21248-1
Security update for jq
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-10392 Уязвимость утилиты для обработки JSON-файлов jq, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
ROS-20260707-73-0009 Уязвимость jq | CVSS3: 7.4 | 0% Низкий | 24 дня назад | |
CVE-2026-41257 jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets. | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-41257 jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets. | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-41257 jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets. | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-41257 jq: Signed-int overflow in `stack_reallocate` (jq VM stack) | 0% Низкий | 3 месяца назад | ||
CVE-2026-41257 jq is a command-line JSON processor. In 1.8.1 and earlier, the jq byte ... | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:21248-1 Security update for jq | 24 дня назад |
Уязвимостей на страницу