Количество 19
Количество 19
CVE-2026-39979
jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.
CVE-2026-39979
jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.
CVE-2026-39979
jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.
CVE-2026-39979
jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers
CVE-2026-39979
jq is a command-line JSON processor. In commits before 2f09060afab23fe ...
BDU:2026-05572
Уязвимость функции jv_parse_sized() функционального языка программирования jq, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260708-73-0052
Уязвимость jq
RLSA-2026:19365
Important: jq security update
RLSA-2026:19151
Important: jq security update
RLSA-2026:16693
Important: jq security update
RLSA-2026:16692
Important: jq security update
RLSA-2026:16252
Important: jq security update
ELSA-2026-19365
ELSA-2026-19365: jq security update (IMPORTANT)
ELSA-2026-19151
ELSA-2026-19151: jq security update (IMPORTANT)
ELSA-2026-16693
ELSA-2026-16693: jq security update (IMPORTANT)
ELSA-2026-16692
ELSA-2026-16692: jq security update (IMPORTANT)
ELSA-2026-16252
ELSA-2026-16252: jq security update (IMPORTANT)
SUSE-SU-2026:2983-1
Security update for jq
openSUSE-SU-2026:21248-1
Security update for jq
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-39979 jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f. | CVSS3: 6.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-39979 jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f. | CVSS3: 8.2 | 1% Низкий | 4 месяца назад | |
CVE-2026-39979 jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f. | CVSS3: 6.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-39979 jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers | 1% Низкий | 4 месяца назад | ||
CVE-2026-39979 jq is a command-line JSON processor. In commits before 2f09060afab23fe ... | CVSS3: 6.5 | 1% Низкий | 4 месяца назад | |
BDU:2026-05572 Уязвимость функции jv_parse_sized() функционального языка программирования jq, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
ROS-20260708-73-0052 Уязвимость jq | CVSS3: 9.1 | 1% Низкий | 25 дней назад | |
RLSA-2026:19365 Important: jq security update | 2 месяца назад | |||
RLSA-2026:19151 Important: jq security update | 2 месяца назад | |||
RLSA-2026:16693 Important: jq security update | 3 месяца назад | |||
RLSA-2026:16692 Important: jq security update | 3 месяца назад | |||
RLSA-2026:16252 Important: jq security update | 3 месяца назад | |||
ELSA-2026-19365 ELSA-2026-19365: jq security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-19151 ELSA-2026-19151: jq security update (IMPORTANT) | 17 дней назад | |||
ELSA-2026-16693 ELSA-2026-16693: jq security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2026-16692 ELSA-2026-16692: jq security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2026-16252 ELSA-2026-16252: jq security update (IMPORTANT) | 3 месяца назад | |||
SUSE-SU-2026:2983-1 Security update for jq | 18 дней назад | |||
openSUSE-SU-2026:21248-1 Security update for jq | 25 дней назад |
Уязвимостей на страницу