PT-2026-32491 · Jq+2 · Jq+2

Highitchy

·

Published

2026-04-13

·

Updated

2026-05-24

·

CVE-2026-32316

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions jq versions prior to 1.8.2
Description An integer overflow occurs within the jvp string append() and jvp string copy replace bad() functions when concatenating strings with a combined length exceeding 2^31 bytes. This leads to a 32-bit unsigned integer overflow during the buffer allocation size calculation, resulting in an undersized heap buffer. Subsequent memory copy operations write the full string data into this buffer, causing a heap-based buffer overflow. This issue stems from a lack of string size bounds checking. An attacker can exploit this by crafting queries that produce extremely large strings to crash the process or achieve heap corruption.
Recommendations Update to a version later than 1.8.1.

Fix

Heap Based Buffer Overflow

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-05376
CVE-2026-32316
ECHO-A148-C5C1-3E42
OESA-2026-1981
OPENSUSE-SU-2026:10850-1
RHSA-2026:8579
USN-8202-1
USN-8202-2

Affected Products

Linuxmint
Ubuntu
Jq