Debian alert DLA-4662-1 (jq)
| From: | Andreas Henriksson <andreas@fatal.se> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4662-1] jq security update | |
| Date: | Wed, 01 Jul 2026 19:44:44 +0200 | |
| Message-ID: | <s4izlf5usbblzbmj4mbofz6ofbe7nxvszivhspcitpznhgorrz@xtfjtplqtsol> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4662-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Andreas Henriksson July 01, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : jq Version : 1.6-2.1+deb12u2 CVE ID : CVE-2026-32316 CVE-2026-33947 CVE-2026-33948 CVE-2026-39956 CVE-2026-39979 CVE-2026-40164 CVE-2026-41256 CVE-2026-41257 CVE-2026-43894 CVE-2026-43895 CVE-2026-43896 CVE-2026-44777 CVE-2026-47770 CVE-2026-49839 CVE-2026-54679 Debian Bug : 1133921 1136445 It was found that jq, a lightweight and flexible command-line JSON parser, was vulnerable to multiple memory corruption attacks, which could lead to application crashes, denial-of-service conditions, and potentially arbitrary code execution through heap corruption when parsing untrusted input. For Debian 12 bookworm, these problems have been fixed in version 1.6-2.1+deb12u2. For Debian 11 bullseye, these issues have been addressed in DLA-4599-1 and DLA-4661-1. We recommend that you upgrade your jq packages. For the detailed security status of jq please refer to its security tracker page at: https://security-tracker.debian.org/tracker/jq Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+uHltkZSvnmOJ4zCC8R9xk0TUwYFAmpFUgoACgkQC8R9xk0T Uwa0pA/+I3Eg39nrzxT0fpd57qIKeLcF7FYYwWFkya3ptx+qx/a9u6lmEnBlKr3T ui9Z6QT69OvHM7ggp5oSLB8GMA36QsZhhexZnb2x6vfa+palHSthQ2xyFXqqbxuQ eB5w1bkCuxv7qPU7JP/FwbvyiucQg3GfYoPaklpsv2Ig/4NWEfknBWk6S2R2/UI+ jCDfwPCxxRjnWzN5LEm6BgmjcJgT51llEU6aB6WP1uZQODG8nN1on6CKXOuZFw1j zuEI+pESgHqXNipEPcicqdzubksGhmKG2cT/Rr1EzOXqx4xUDgOMTNQjOU2h+r+8 rGjMMX3Dk76Q483EZZBbZZvoJV5AhhxvsRSFd4w5EokDpp6wEb2g0hYaTeV+cRzi uIKVkXdiLCMNLpCsf86+lDYMjfjNDXLgDTxzGURCl5NbYaGIZB2qAmB88Ed5wtBv cvcCE+R6WfaGce9t5P1AGpVKJsg8KRDvYGY65WT9LBonTNwepHhRJl0Lh6Dr8jdl 8VvYq67oDbpbMPYnsIxQCi1yPHitj3BnIpUMepZwiz0K1LDo213BL6AzfFTJ5EDx tRjLUokTaWLVOCRrVHJRkTxQIaSEDU6Prn6Ptf6iANdM65HxXqk0KM2aBsbYMhRw LiTwACH9BFEwYe/kU3wNeBp16ehbQ4BBr99q12MqX0vgxb+PhH8= =PTYe -----END PGP SIGNATURE-----
