Debian alert DLA-4661-1 (jq)
| From: | Andreas Henriksson <andreas@fatal.se> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4661-1] jq security update | |
| Date: | Wed, 01 Jul 2026 16:26:45 +0200 | |
| Message-ID: | <vk4f4eetlntnz2yfhwqeozit6agepfz5kruds3vms2nm645oge@d2t5hgpnrb6j> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4661-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Andreas Henriksson July 01, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : jq Version : 1.6-2.1+deb11u3 CVE ID : CVE-2026-43894 CVE-2026-47770 CVE-2026-49839 CVE-2026-54679 Debian Bug : 1136445 It was found that jq, a lightweight and flexible command-line JSON parser, was vulnerable to multiple memory corruption attacks, which could lead to application crashes, denial-of-service conditions, and potentially arbitrary code execution through heap corruption when parsing untrusted input. For Debian 11 bullseye, these problems have been fixed in version 1.6-2.1+deb11u3. We recommend that you upgrade your jq packages. For the detailed security status of jq please refer to its security tracker page at: https://security-tracker.debian.org/tracker/jq Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+uHltkZSvnmOJ4zCC8R9xk0TUwYFAmpFI6UACgkQC8R9xk0T UwbHJw//Y/PLMza/XQt4lL7ZRfDUGKOM/FOxL14kIwuAnPWXQ7RbOYbQ2kvv9fWf t3xrcUfA31rKjMcwYm7fGSGvNUm48ib7UHy63ulHEGGpQJv7UhQ4m3OnyALiOkLV nLC8Bvz5kRApRaaMx44pvtPiYN0EgvUC5eRCSLEGD8Leh+EThu1CsXCvzkKkWM1/ k0FeKDdhYT1jSIb3w4Z5sVq4i6pWHaKAjDb8jdXOwO6nRoqCiXepqn/5cQ0/wlcW eGl4kKKOcrC1E0RFzvALPyfpoRc0mAS3yrzpQqdXKlJ7IXUKAB51eDGi2hpuoklI JVh9a/+EOYAkxToQ4cS/CqlyWDEV35sByEzbBU02b5CHGyTmGyKbxKWiryDn2qFi n6aez+GJfRQBR+dsD6Hl078i7VnQdhuDZi9xNn+Hgcea+P41QWOg5SMKT0sCsqTy HdqC3IPRWcd8k9yjXz+k8aOmWVzUbTWqvl334hK5IA538brsX7RC8os2Q+dp6FoU BZgU/CutErYXCumLQaFB8HZb6hqVmBfAWSwwA/hn+b5gF1rToyXXq9IhEdyI0XJk VEKc5GdRN7q5UYL1a8OY7MxhsjKn5EcJOdaj/f4528YFuOx2Oyr6T/aJEywXmM9z 0Xprv+tThOeEzsea1zQ2zgtfMu4SQ/8TupqDByHY7KNTCRVYdqY= =+sik -----END PGP SIGNATURE-----
