[ALSA-2025:10585] Moderate: jq security update
Type:
security
Severity:
moderate
Release date:
2025-07-10
Description:
jq is a lightweight and flexible command-line JSON processor. jq is like sed for JSON data. You can use it to slice, filter, map, or transform structured data with the same ease that sed, awk, grep, or similar applications allow you to manipulate text. Security Fix(es): * jq: jq has signed integer overflow in jv.c:jvp_array_write (CVE-2024-23337) * jq: AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt) (CVE-2025-48060) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 jq-1.6-17.el9_6.2.aarch64.rpm 21c4633377b554a2fa14710d678bec5a09170ab676ba7388b555fdb248469ec8
aarch64 jq-devel-1.6-17.el9_6.2.aarch64.rpm 9ce84d6f1d1e3282d818288a870d64f6016110a03f8e26252b85753a65c90734
i686 jq-devel-1.6-17.el9_6.2.i686.rpm 89e2102bf4c8f5665161fee4c1f59aa3f1f97195dbcb7040be830dfce95d6441
i686 jq-1.6-17.el9_6.2.i686.rpm c3c541c0f1e9462fe03d044bc51d32cb0a5ee7bec288c36b0d15e67d5652e13f
ppc64le jq-devel-1.6-17.el9_6.2.ppc64le.rpm 7c49336122ac33da0c5f118bbebc0a15eec2640d6adb7e569725ae248c92d104
ppc64le jq-1.6-17.el9_6.2.ppc64le.rpm 9683c0e6ae01e6a2f09de557c1123640e1e2fcdf83bb2d7333e8b3a15578580a
s390x jq-devel-1.6-17.el9_6.2.s390x.rpm 20d1faa02ec582b64cbbc670b3fc3bee5200f7038fb49bb7906d7853ebc1b96f
s390x jq-1.6-17.el9_6.2.s390x.rpm dbe4d531548af04561a2549a95056645f637e67ba8e4eed9579fe81118cb619e
x86_64 jq-1.6-17.el9_6.2.x86_64.rpm 4ee2d6d9859dd6254ab82332c23fd2764b9385497512af90349edc83fe6e47eb
x86_64 jq-devel-1.6-17.el9_6.2.x86_64.rpm b80c5dc06c3d57a737b0f2d617c89f15ad96c3cdd3e623e85aa65d5d41b6c70b
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.