|
|
Log in / Subscribe / Register

Ubuntu alert USN-7657-2 (jq)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7657-2] jq vulnerabilities
Date:  Wed, 23 Jul 2025 07:19:59 +0000
Message-ID:  <E1ueTlf-00060H-NJ@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-7657-2 July 22, 2025 jq vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in jq. Software Description: - jq: lightweight and flexible command-line JSON processor Details: USN-7657-1 fixed CVE-2024-23337 and CVE-2025-48060 in jq. This update provides the corresponding fixes for Ubuntu 20.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 16.04 LTS. Original advisory details: It was discovered that jq incorrectly handled certain values when parsing JSON data. A remote attacker could possibly use this issue to cause jq to crash, resulting in a denial of service. (CVE-2024-23337) It was discovered that jq incorrectly handled certain values when parsing JSON data. A remote attacker could use this issue to cause jq to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2025-48060) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS jq 1.6-1ubuntu0.20.04.1+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS jq 1.5+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS jq 1.5+dfsg-1ubuntu0.1+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7657-2 https://ubuntu.com/security/notices/USN-7657-2 CVE-2024-23337, CVE-2025-48060


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmiAjQ4ACgkQcpJm3tlz hgFORA//d11Ko/Xa4uOxqxHYRc1ia0d21A1IDBStQHVtm17030+PdmeL9863Rf39 3A1sUatcQrdCgNaffkOj9xLJHEfD2c+YvRFbexmQZbTgwPWA38SO/07QZ4aAZ3qI aNPmt9VSa6IdUP9oSw9VuzUqIky83GF0OIt3z5KevmqBmq8wc8Z/LQ5X7898bfKZ 2wKXfwZ9UIHBOXLaZgZ/VhL5F7XumECx/qVBwEi2yUab9hM+NO9eox9R2nIUA6vw tpHeVSxP/MJlxDaUsYFPVCACsNugnnCK/9bIZ2Lhz0bOEF5A9l+RLAKm5DUwCahz f59AEHZIqgSDJIGsXwxVHjDlOaJioiWnbPtRqL5feIxW+uihM8tQKJfov5aH9X1Y ewq377khoO0yVpddHYHe7Gxk6GT0Z+XzOg84Id//mMmfcliF+HHVG+CDMT21wrDd A/x9ANHtkB8fdldy+vzI8lb1SIrW5tga6QeWdCV/05S5Q8rkik98Z9NC27kwebHu dP/nEL13xhmY76POsaH2N/paPvev/9wRsTbUB+Qnm2QxY3CRfGz1GkYH0kpQ8pee ldS8qXIV0Gfa9tcNs8iX665mVOMk2LN+AblK2JDOkkaToxtJizuo6gaBni8F0HOk aKYLO72KRglikdpmsO7NtJ2pN1ia5UiR2oRm8hA+d9GAXhkGbk0= =kPvD -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds