USN-7657-1 fixed CVE-2024-23337 and CVE-2025-48060 in jq. This update provides the corresponding fixes for Ubuntu 20.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 16.04 LTS.
Original advisory details:
It was discovered that jq incorrectly handled certain values when parsing JSON data. A remote attacker could possibly use this issue to cause jq to crash, resulting in a denial of service. (CVE-2024-23337)
It was discovered that jq incorrectly handled certain values when parsing JSON data. A remote attacker could use this issue to cause jq to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2025-48060)
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_name": "jq", "binary_version": "1.5+dfsg-2ubuntu0.1~esm1" }, { "binary_name": "jq-dbgsym", "binary_version": "1.5+dfsg-2ubuntu0.1~esm1" }, { "binary_name": "libjq-dev", "binary_version": "1.5+dfsg-2ubuntu0.1~esm1" }, { "binary_name": "libjq1", "binary_version": "1.5+dfsg-2ubuntu0.1~esm1" }, { "binary_name": "libjq1-dbgsym", "binary_version": "1.5+dfsg-2ubuntu0.1~esm1" } ] }
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "binaries": [ { "binary_name": "jq", "binary_version": "1.6-1ubuntu0.20.04.1+esm1" }, { "binary_name": "jq-dbgsym", "binary_version": "1.6-1ubuntu0.20.04.1+esm1" }, { "binary_name": "libjq-dev", "binary_version": "1.6-1ubuntu0.20.04.1+esm1" }, { "binary_name": "libjq1", "binary_version": "1.6-1ubuntu0.20.04.1+esm1" }, { "binary_name": "libjq1-dbgsym", "binary_version": "1.6-1ubuntu0.20.04.1+esm1" } ] }