VDB
RHSA-2026%3A18042
RHSA-2026%3A18042
PUBLISHED
CVSS 8.199999809265137 HIGH
A flaw was found in jq, a command line JSON processor, specifically in the libjq API. Parsing a malformed JSON input from a non-NUL-terminated buffer using the `jv_parse_sized` function can cause an out-of-bounds read, resulting in an application crash and a possible memory disclosure within the error message generated by the parser.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | jq-debuginfo-0:1.6-17.el9_6.4.s390x as a component of Red Hat CodeReady Linux Builder EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-debuginfo-0:1.6-17.el9_6.4.ppc64le as a component of Red Hat CodeReady Linux Builder EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-devel-0:1.6-17.el9_6.4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-0:1.6-17.el9_6.4.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-devel-0:1.6-17.el9_6.4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-devel-0:1.6-17.el9_6.4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-debuginfo-0:1.6-17.el9_6.4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-devel-0:1.6-17.el9_6.4.i686 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-devel-0:1.6-17.el9_6.4.i686 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-debugsource-0:1.6-17.el9_6.4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-0:1.6-17.el9_6.4.i686 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-devel-0:1.6-17.el9_6.4.s390x as a component of Red Hat CodeReady Linux Builder EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-devel-0:1.6-17.el9_6.4.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-debugsource-0:1.6-17.el9_6.4.s390x as a component of Red Hat CodeReady Linux Builder EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-0:1.6-17.el9_6.4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-0:1.6-17.el9_6.4.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-devel-0:1.6-17.el9_6.4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-debugsource-0:1.6-17.el9_6.4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-debuginfo-0:1.6-17.el9_6.4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6) | 1.6-17.el9 |
| Red Hat | jq-debugsource-0:1.6-17.el9_6.4.i686 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6) | 1.6-17.el9 |
…and 22 more
Timeline
- May 18, 2026 CVE Published
- May 18, 2026 CVE Updated
- May 18, 2026 Distribution Patch
- May 18, 2026 Distribution Patch
- May 18, 2026 Security Advisory
- May 18, 2026 Security Advisory
- May 18, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2026:18042 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2458077 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2458084 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_18042.json advisory
- https://access.redhat.com/security/cve/CVE-2026-39979 advisory
- https://www.cve.org/CVERecord?id=CVE-2026-39979 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-39979 advisory
- https://github.com/jqlang/jq/commit/2f09060afab23fe9390cce7cb860b10416e1bf5f advisory
- https://github.com/jqlang/jq/security/advisories/GHSA-2hhh-px8h-355p advisory
- https://access.redhat.com/security/cve/CVE-2026-40164 advisory
- https://www.cve.org/CVERecord?id=CVE-2026-40164 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-40164 advisory
- https://github.com/jqlang/jq/commit/0c7d133c3c7e37c00b6d46b658a02244fdd3c784 advisory
- https://github.com/jqlang/jq/security/advisories/GHSA-wwj8-gxm6-jc29 advisory