[CLSA-2026:1778143159] jq: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-05-07 08:39:25 UTC
Description:
- CVE-2026-33948: fix NUL truncation in JSON parser (validation bypass) - CVE-2026-33947: fix unbounded recursion stack overflow in jv_setpath/getpath/delpaths
Updated packages:
  • jq-1.6-17.el9_6.2.tuxcare.els2.i686.rpm
    sha:09cc6badea38b1dd5327f35351630c48b10ea6cb98d91cec92e88008860ddf8f
  • jq-1.6-17.el9_6.2.tuxcare.els2.x86_64.rpm
    sha:f0b85033f44ff7a21a5747eba35d40390967b94b904f001ba8cdf8be5bd90d7e
  • jq-devel-1.6-17.el9_6.2.tuxcare.els2.i686.rpm
    sha:2e9ab7e4cb7c168fc2a7e60a30cc2f7b6a07c44edcf34967299f5fd866160950
  • jq-devel-1.6-17.el9_6.2.tuxcare.els2.x86_64.rpm
    sha:c03827523a0a01127c0fa51470936f2a45d72fb87f1c2d4658ab6b94404da227
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.