[ALSA-2026:19365] Important: jq security update
Type:
security
Severity:
important
Release date:
2026-05-26
Description:
jq is a lightweight and flexible command-line JSON processor. jq is like sed for JSON data. You can use it to slice, filter, map, or transform structured data with the same ease that sed, awk, grep, or similar applications allow you to manipulate text. Security Fix(es): * jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers (CVE-2026-39979) * jq: jq: Denial of Service via crafted JSON object causing hash collisions (CVE-2026-40164) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 jq-1.6-19.el9_8.2.aarch64.rpm 71bdbbfbd999c29ade00444fc6c6357b204cf8954e8f68e49ab2e0fa01361f38
aarch64 jq-devel-1.6-19.el9_8.2.aarch64.rpm c8ecc41814c11ab3cfa1407bd1c9c2c36107b911aedd0413ca1dd2de6d703e8e
i686 jq-1.6-19.el9_8.2.i686.rpm 1f4dd7e661abd0dda2eb1ff439cd33586e9b0e4cd49303d4516524c135bde7a7
i686 jq-devel-1.6-19.el9_8.2.i686.rpm f6928d8cd047f9264c3c48574c7d9ec8f73048c7484a83eb87d428ad98ac5241
ppc64le jq-devel-1.6-19.el9_8.2.ppc64le.rpm 92ee4f2a719ff3c70eeb4b121ba9d013f58d32896a01bc22616fb2d73e4a47dc
ppc64le jq-1.6-19.el9_8.2.ppc64le.rpm bbf4e9fba3359f63a2372d1f350c44e0dd964a0e3909cb916686f10da842b384
s390x jq-devel-1.6-19.el9_8.2.s390x.rpm c62d4768b38acf5e2211fbc27f053ba35504755b39ecac154cde984db66e8edc
s390x jq-1.6-19.el9_8.2.s390x.rpm d9f49b74f0f70cc49db5d56093416464c6753981c4538db38147e4b2f2987a35
x86_64 jq-devel-1.6-19.el9_8.2.x86_64.rpm 005944df9ca3eb8fb0dcfad35d0577ac857bc0f5a03375e658694c17f3552ab3
x86_64 jq-1.6-19.el9_8.2.x86_64.rpm 395b58a720a57f5f5981e3c3b48f3fde6f48f337413d917999c86d57b39287aa
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.