Integer overflow in jq - CVE-2026-32316
Published: April 13, 2026 / Updated: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow in the "jvp_string_append" and "jvp_string_copy_replace_bad" functions. A remote attacker can pass specially crafted data to the application, trigger integer overflow and cause a denial of service condition on the target system.
Affected software
Debian Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Ubuntu
Basesystem Module
openEuler
Fedora
LANTIME Operating System Firmware (LTOS)
jq (Ubuntu package)
jq-debuginfo
libjq1-debuginfo
libjq1
jq-debugsource
jq
libjq-devel
jq (Debian package)
jq-help
jq-devel
How to mitigate CVE-2026-32316
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
jq (Ubuntu package) - addressed in versions 1.3-1.1ubuntu1.1+esm4, 1.5+dfsg-1ubuntu0.1+esm4, 1.5+dfsg-2ubuntu0.1~esm2, 1.5+dfsg-2ubuntu0.1~esm3, 1.6-1ubuntu0.20.04.1+esm2, 1.6-1ubuntu0.20.04.1+esm3, 1.6-2.1ubuntu3.2, 1.7.1-3ubuntu0.24.04.2, 1.8.1-3ubuntu1.1, 1.8.1-4ubuntu2
jq-debuginfo - update to 1.6-150000.3.20.1
libjq1-debuginfo - update to 1.6-150000.3.20.1
libjq1 - update to 1.6-150000.3.20.1
jq-debugsource - update to 1.6-150000.3.20.1
jq - update to 1.6-150000.3.20.1
libjq-devel - update to 1.6-150000.3.20.1
jq (Debian package) - update to 1.7.1-6+deb13u3
jq-help - update to 1.8.0-3
jq-devel - update to 1.8.0-3
jq-debugsource - update to 1.8.0-3
jq-debuginfo - update to 1.8.0-3
jq - update to 1.8.0-3
jq - update to 1.8.1-3.fc44