[CLSA-2026:1777322146] jq: Fix of CVE-2026-32316
Type:
security
Severity:
Important
Release date:
2026-04-27 20:35:51 UTC
Description:
- CVE-2026-32316: fix heap buffer overflow in jvp_string_append and jvp_string_copy_replace_bad caused by uint32_t overflow in size calculations for strings exceeding INT_MAX bytes
Updated packages:
  • jq-1.6-14.el9.tuxcare.els3.i686.rpm
    sha:a0c533861f957bc666a43319a369b630f9b7ead1e0d1e7f55a90be45e855739e
  • jq-1.6-14.el9.tuxcare.els3.x86_64.rpm
    sha:3b93fa932a2b82313e4beb699eb527e04e8ff903658e7ae520e0bf1a66c46b57
  • jq-devel-1.6-14.el9.tuxcare.els3.i686.rpm
    sha:780548fe509b284908fb6cd0c3a782b9e3f5e88a3b54ee846a5999523dc6c38a
  • jq-devel-1.6-14.el9.tuxcare.els3.x86_64.rpm
    sha:813237af873a5a7d18b6499c4a90232db0bc1eefe9d8ccac94ae02f46ca30b7a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.