[ALSA-2026:16692] Important: jq security update
Type:
security
Severity:
important
Release date:
2026-05-16
Description:
jq is a lightweight and flexible command-line JSON processor. jq is like sed for JSON data. You can use it to slice, filter, map, or transform structured data with the same ease that sed, awk, grep, or similar applications allow you to manipulate text. Security Fix(es): * jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers (CVE-2026-39979) * jq: jq: Denial of Service via crafted JSON object causing hash collisions (CVE-2026-40164) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 jq-devel-1.7.1-11.el10_1.0.2.aarch64.rpm 2f46b2218da2847e592712ffc5ff4f781c275608117554b127e8587b8a0c2eee
aarch64 jq-1.7.1-11.el10_1.0.2.aarch64.rpm 9a4fa7c581288a36a04a6d4448424c13ca42b16f47030e1fc2598f7d58f13462
ppc64le jq-1.7.1-11.el10_1.0.2.ppc64le.rpm ae529b983222b666b09744c95e7a0b14f184109e37ad67b9427d90255359fc1d
ppc64le jq-devel-1.7.1-11.el10_1.0.2.ppc64le.rpm b490d669fcb925a3e4439df6414486e50f35dd51c8b3a27ea87f4576f4ae7ece
s390x jq-1.7.1-11.el10_1.0.2.s390x.rpm 119225962cecaa00911a7099e9844f9d07dd6f2c6f0dc5f139b82fa7c156f2af
s390x jq-devel-1.7.1-11.el10_1.0.2.s390x.rpm 886ddfd968b32711b9c836dd919f9f060566fdb179f30441ae22f27557bf7abd
x86_64 jq-devel-1.7.1-11.el10_1.0.2.x86_64.rpm 1dd33a950a4c975e4a9da6a2d12bed6af671aa910ad4a2b83a66dfdbd0f23657
x86_64 jq-1.7.1-11.el10_1.0.2.x86_64.rpm 35c2ad2a89c625ed3908309858a321d8c5413e18b274976eb0cdc946aefd64d8
x86_64_v2 jq-1.7.1-11.el10_1.0.2.x86_64_v2.rpm 3477815a861d547d5298ae1b59d7cb36e37ec21e05365be93d4f94ad70e5443f
x86_64_v2 jq-devel-1.7.1-11.el10_1.0.2.x86_64_v2.rpm ffe3296bda01499de98e6f550337ed63cefd476b0d732ebd95e58a4e904fc0d9
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.