SUSE-SU-2026:4275-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264275-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4275-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:4275-1
Upstream
CVE (17)
Related
Published
2026-09-21T07:33:03Z
Modified
2026-09-21T17:15:11Z
Summary
Security update for jq
Details

This update for jq fixes the following issues:

Security issues fixed:

  • CVE-2015-8863: heap buffer overflow in tokenadd() function (bsc#976992).
  • CVE-2023-50246: improper memory handling can lead to a heap buffer overflow in decNumberToString (bsc#1218034).
  • CVE-2023-50268: stack-based buffer overflow in builds using decNumber (bsc#1218038).
  • CVE-2024-53427: stack-buffer-overflow in the decNumberCopy function in decNumber.c (bsc#1238078).
  • CVE-2025-9403: reachable assertion in run_jq_tests() (bsc#1248600).
  • CVE-2026-33948: CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043).
  • CVE-2026-40164: predictable hash collisions can lead to a denial of service (bsc#1262072).
  • CVE-2026-40612: jv_contains recurses into nested arrays/objects with no depth limit and can cause a stack overflow (bsc#1265060).
  • CVE-2026-41256: embedded NUL truncates top-level jq programs loaded with -f and can lead to execution of unintended programs (bsc#1265061).
  • CVE-2026-41257: integer overflow in stack_reallocate can lead to memory corruption and DoS (bsc#1265062).
  • CVE-2026-43894: signed integer overflow in decNumber can lead to out-of-bounds memory write (bsc#1265070).
  • CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure (bsc#1265071).
  • CVE-2026-43896: unbounded recursion in jv_object_merge_recursive() can lead to C stack exhaustion and a process crash (bsc#1265075).
  • CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules include each other can lead to stack exhaustion and process crash (bsc#1265076).
  • CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221).
  • CVE-2026-49839: --rawfile invalid-state reuse after String too long can lead to a heap buffer overflow (bsc#1269220).
  • CVE-2026-54679: integer overflow in jvp_string_append can lead to a buffer overrun on 32-bit systems (bsc#1269390).

Changes for jq:

Update to version 1.7.1:

  • Make the default background color more suitable for bright backgrounds.
  • Allow passing the inline jq script after --.
  • Fix possible uninitialised value dereference if jq_init() fails
  • Simplify paths/0 and paths/1.
  • Reject U+001F in string literals.
  • Remove unused nref accumulator in block_bind_library.
  • Remove a bunch of unused variables, and useless assignments.
  • main.c: Remove unused EXIT_STATUS_EXACT option.
  • Actually use the number correctly casted from double to int as index.
  • src/builtin.c: remove unnecessary jv_copy-s in type_error/type_error2.
  • Remove undefined behavior caught by LLVM 10 UBSAN.
  • Convert decnum to binary64 (double) instead of decimal64. This makes jq behave like the JSON specification suggests and more similar to other languages.
  • Fix memory leaks on invalid input for ltrimstr/1 and rtrimstr/1.
  • Fix memory leak on failed get for setpath/2.
  • Fix nan from json parsing also for nans with payload that start with 'n'.
  • Allow carriage return characters in comments.
  • Generate links in the man page.
  • Add extern C for C++.
  • Make object key color configurable using JQ_COLORS environment variable.
  • Change the default color of null to Bright Black.
  • Respect NO_COLOR environment variable to disable color output.
  • Improved --help output. Now mentions all options and nicer order.
  • Fix multiple issues of exit code using --exit-code/-e option.
  • Add --raw-output0 for NUL (zero byte) separated output.
  • Fix assert crash and validate JSON for --jsonarg.
  • Remove deprecated --argfile option.
  • Use decimal number literals to preserve precision. Comparison operations respects precision but arithmetic operations might truncate.
  • Adds new builtin pick(stream) to emit a projection of the input object or array.
  • Adds new builtin debug(msgs) that works like debug but applies a filter on the input before writing to stderr.
  • Adds new builtin scan($re; $flags). Was documented but not implemented.
  • Adds new builtin abs to get absolute value. This potentially allows the literal value of numbers to be preserved as length and fabs convert to float.
  • Allow if without else-branch. When skipped the else-branch will be . (identity).
  • Allow use of $binding as key in object literals.
  • Allow dot between chained indexes when using .['index']
  • Allow dot for chained value iterator .[], .[]?
  • Fix try/catch catches more than it should.
  • Speed up and refactor some builtins, also remove scalars_or_empty/0.
  • Now halt and halt_error exit immediately instead of continuing to the next input.
  • Fix issue converting string to number after previous convert error.
  • Fix issue representing large numbers on some platforms causing invalid JSON output.
  • Fix deletion using assigning empty against arrays.
  • Allow keywords to be used as binding name in more places.
  • Allow using nan as NaN in JSON.
  • Expose a module's function names in modulemeta.
  • Fix contains/1 to handle strings with NUL.
  • Fix stderr/0 to output raw text without any decoration.
  • Fix nth/2 to emit empty on index out of range.
  • Fix implode to not assert and instead replace invalid unicode codepoints.
  • Fix indices/1 and rindex/1 in case of overlapping matches in strings.
  • Fix sub/3 to resolve issues involving global search-and-replace (gsub) operations.
  • Fix empty regular expression matches.
  • Fix overflow exception of the modulo operator.
  • Fix string multiplication by 0 (and less than 1) to emit empty string.
  • Fix segfault when using libjq and threads.
  • Fix constant folding of division and reminder with zero divisor.
  • Fix error/0, error/1 to throw null error.
  • Simpler and faster transpose.
  • Simple and efficient implementation of walk/1.
  • Remove deprecated filters leaf_paths, recurse_down.
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
jq

Package

Name
jq
Purl
pkg:rpm/suse/jq&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.1-150000.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "jq":  "1.7.1-150000.3.25.1",
            "libjq-devel":  "1.7.1-150000.3.25.1",
            "libjq1":  "1.7.1-150000.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4275-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
jq

Package

Name
jq
Purl
pkg:rpm/suse/jq&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.1-150000.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "jq":  "1.7.1-150000.3.25.1",
            "libjq-devel":  "1.7.1-150000.3.25.1",
            "libjq1":  "1.7.1-150000.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4275-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
jq

Package

Name
jq
Purl
pkg:rpm/suse/jq&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.1-150000.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "jq":  "1.7.1-150000.3.25.1",
            "libjq-devel":  "1.7.1-150000.3.25.1",
            "libjq1":  "1.7.1-150000.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4275-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
jq

Package

Name
jq
Purl
pkg:rpm/suse/jq&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.1-150000.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "jq":  "1.7.1-150000.3.25.1",
            "libjq-devel":  "1.7.1-150000.3.25.1",
            "libjq1":  "1.7.1-150000.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4275-1.json"
SUSE:Linux Enterprise Micro 5.3
jq

Package

Name
jq
Purl
pkg:rpm/suse/jq&distro=SUSE%20Linux%20Enterprise%20Micro%205.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.1-150000.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "jq":  "1.7.1-150000.3.25.1",
            "libjq1":  "1.7.1-150000.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4275-1.json"
SUSE:Linux Enterprise Micro 5.4
jq

Package

Name
jq
Purl
pkg:rpm/suse/jq&distro=SUSE%20Linux%20Enterprise%20Micro%205.4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.1-150000.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "jq":  "1.7.1-150000.3.25.1",
            "libjq1":  "1.7.1-150000.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4275-1.json"
SUSE:Linux Enterprise Micro 5.5
jq

Package

Name
jq
Purl
pkg:rpm/suse/jq&distro=SUSE%20Linux%20Enterprise%20Micro%205.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.1-150000.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "jq":  "1.7.1-150000.3.25.1",
            "libjq1":  "1.7.1-150000.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4275-1.json"
SUSE:Linux Enterprise Module for Basesystem 15 SP7
jq

Package

Name
jq
Purl
pkg:rpm/suse/jq&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.1-150000.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "jq":  "1.7.1-150000.3.25.1",
            "libjq-devel":  "1.7.1-150000.3.25.1",
            "libjq1":  "1.7.1-150000.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4275-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
jq

Package

Name
jq
Purl
pkg:rpm/suse/jq&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.1-150000.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "jq":  "1.7.1-150000.3.25.1",
            "libjq-devel":  "1.7.1-150000.3.25.1",
            "libjq1":  "1.7.1-150000.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4275-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
jq

Package

Name
jq
Purl
pkg:rpm/suse/jq&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.1-150000.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "jq":  "1.7.1-150000.3.25.1",
            "libjq-devel":  "1.7.1-150000.3.25.1",
            "libjq1":  "1.7.1-150000.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4275-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
jq

Package

Name
jq
Purl
pkg:rpm/suse/jq&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.1-150000.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "jq":  "1.7.1-150000.3.25.1",
            "libjq-devel":  "1.7.1-150000.3.25.1",
            "libjq1":  "1.7.1-150000.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4275-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
jq

Package

Name
jq
Purl
pkg:rpm/suse/jq&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.1-150000.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "jq":  "1.7.1-150000.3.25.1",
            "libjq-devel":  "1.7.1-150000.3.25.1",
            "libjq1":  "1.7.1-150000.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4275-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
jq

Package

Name
jq
Purl
pkg:rpm/suse/jq&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.1-150000.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "jq":  "1.7.1-150000.3.25.1",
            "libjq-devel":  "1.7.1-150000.3.25.1",
            "libjq1":  "1.7.1-150000.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4275-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
jq

Package

Name
jq
Purl
pkg:rpm/suse/jq&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.1-150000.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "jq":  "1.7.1-150000.3.25.1",
            "libjq-devel":  "1.7.1-150000.3.25.1",
            "libjq1":  "1.7.1-150000.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4275-1.json"