Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:18048: Important: jq security update

This advisory addresses two vulnerabilities in the `jq` JSON processor: an out-of-bounds read in `jv_parse_sized()` (CVE-2026-39979, CVSS 6.5 MEDIUM) and a denial-of-service via hash collisions from crafted JSON objects (CVE-2026-40164, CVSS 7.5 HIGH). The out-of-bounds read affects jqlang jq versions prior to the fixed release dated 2026-04-12. Red Hat has rated this update as Important and provides patched packages for specific RHEL 8.4 support extensions.
Read Full Article →

Red Hat Product Errata RHSA-2026:18048 - Security Advisory Issued: 2026-05-18 Updated: 2026-05-18 RHSA-2026:18048 - Security Advisory Overview Updated Packages Synopsis Important: jq security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for jq is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description jq is a lightweight and flexible command-line JSON processor. jq is like sed for JSON data. You can use it to slice, filter, map, or transform structured data with the same ease that sed, awk, grep, or similar applications allow you to manipulate text. Security Fix(es): jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers (CVE-2026-39979) jq: jq: Denial of Service via crafted JSON object causing hash collisions (CVE-2026-40164) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2458077 - CVE-2026-39979 jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers BZ - 2458084 - CVE-2026-40164 jq: jq: Denial of Service via crafted JSON object causing hash collisions CVEs CVE-2026-39979 CVE-2026-40164 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 SRPM jq-1.5-12.el8_4.5.src.rpm SHA-256: 119d73e30eb25d76b33c0742810511d612dbf1aa40ba42194299a5f6344eb49a x86_64 jq-1.5-12.el8_4.5.i686.rpm SHA-256: 706b97f35cbea8c9d455d0097ddc836877d29b67355979cf42ed9ebed6f75c7b jq-1.5-12.el8_4.5.x86_64.rpm SHA-256: 449446b3d86f17c6e8b83e7ebde4190de3bcd138184abf7c7733573466f83374 jq-debuginfo-1.5-12.el8_4.5.i686.rpm SHA-256: 8fa3a5a1d6d68d6c2c753d69f72130c078826d916898108162d9b4f81620d4ef jq-debuginfo-1.5-12.el8_4.5.x86_64.rpm SHA-256: 47f415689e52d901cbaea8a6abeb07d065eea9e93b16cd9eab3b5f1746b4d7c9 jq-debugsource-1.5-12.el8_4.5.i686.rpm SHA-256: 10cc6e74d5875aa2fa0f3998991d1f7536286c9ce3f1d0c8753ffeb4384d5ad2 jq-debugsource-1.5-12.el8_4.5.x86_64.rpm SHA-256: 0f6f704fd89a4fc317c606f6c7b7bad39a9511452a7f51117ab343401f9665a9 Red Hat Enterprise Linux Server - AUS 8.4 SRPM jq-1.5-12.el8_4.5.src.rpm SHA-256: 119d73e30eb25d76b33c0742810511d612dbf1aa40ba42194299a5f6344eb49a x86_64 jq-1.5-12.el8_4.5.i686.rpm SHA-256: 706b97f35cbea8c9d455d0097ddc836877d29b67355979cf42ed9ebed6f75c7b jq-1.5-12.el8_4.5.x86_64.rpm SHA-256: 449446b3d86f17c6e8b83e7ebde4190de3bcd138184abf7c7733573466f83374 jq-debuginfo-1.5-12.el8_4.5.i686.rpm SHA-256: 8fa3a5a1d6d68d6c2c753d69f72130c078826d916898108162d9b4f81620d4ef jq-debuginfo-1.5-12.el8_4.5.x86_64.rpm SHA-256: 47f415689e52d901cbaea8a6abeb07d065eea9e93b16cd9eab3b5f1746b4d7c9 jq-debugsource-1.5-12.el8_4.5.i686.rpm SHA-256: 10cc6e74d5875aa2fa0f3998991d1f7536286c9ce3f1d0c8753ffeb4384d5ad2 jq-debugsource-1.5-12.el8_4.5.x86_64.rpm SHA-256: 0f6f704fd89a4fc317c606f6c7b7bad39a9511452a7f51117ab343401f9665a9 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article