jq: backport fix for CVE-2026-32316 #2
No reviewers
Labels
No labels
auto-analysis
cve
match-cpe-range
needs-triage
security
severity-high
source-niceos-scan
source-nvd
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
rpms/jq!2
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "cve-jq-CVE-2026-32316"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This update backports the upstream fix for CVE-2026-32316 in jq 1.8.1-1.
The vulnerability is an integer overflow in jvp_string_append() and jvp_string_copy_replace_bad() that can allocate an undersized heap buffer when very large strings are concatenated. Subsequent writes may overflow the heap, causing process crashes and potentially enabling exploitation through heap corruption.
NiceOS jq 1.8.1-1 is within the affected range, so the package should be treated as affected until the upstream fix is backported.
Validation planned: