Integer overflow in jq - CVE-2026-32316

 

Integer overflow in jq - CVE-2026-32316

Published: April 13, 2026 / Updated: August 19, 2026


Vulnerability identifier: #VU125833
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-32316
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to integer overflow in the "jvp_string_append" and "jvp_string_copy_replace_bad" functions. A remote attacker can pass specially crafted data to the application, trigger integer overflow and cause a denial of service condition on the target system.


Affected software

jq
Debian Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Ubuntu
Basesystem Module
openEuler
Fedora
LANTIME Operating System Firmware (LTOS)
jq (Ubuntu package)
jq-debuginfo
libjq1-debuginfo
libjq1
jq-debugsource
jq
libjq-devel
jq (Debian package)
jq-help
jq-devel

How to mitigate CVE-2026-32316

Install update from vendor's website.

jq - update to 1.8.2
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
jq (Ubuntu package) - addressed in versions 1.3-1.1ubuntu1.1+esm4, 1.5+dfsg-1ubuntu0.1+esm4, 1.5+dfsg-2ubuntu0.1~esm2, 1.5+dfsg-2ubuntu0.1~esm3, 1.6-1ubuntu0.20.04.1+esm2, 1.6-1ubuntu0.20.04.1+esm3, 1.6-2.1ubuntu3.2, 1.7.1-3ubuntu0.24.04.2, 1.8.1-3ubuntu1.1, 1.8.1-4ubuntu2
jq-debuginfo - update to 1.6-150000.3.20.1
libjq1-debuginfo - update to 1.6-150000.3.20.1
libjq1 - update to 1.6-150000.3.20.1
jq-debugsource - update to 1.6-150000.3.20.1
jq - update to 1.6-150000.3.20.1
libjq-devel - update to 1.6-150000.3.20.1
jq (Debian package) - update to 1.7.1-6+deb13u3
jq-help - update to 1.8.0-3
jq-devel - update to 1.8.0-3
jq-debugsource - update to 1.8.0-3
jq-debuginfo - update to 1.8.0-3
jq - update to 1.8.0-3
jq - update to 1.8.1-3.fc44

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins