NULL pointer dereference in jq - CVE-2026-39956

 

NULL pointer dereference in jq - CVE-2026-39956

Published: April 13, 2026 / Updated: August 19, 2026


Vulnerability identifier: #VU125840
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-39956
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to jq _strindices missing runtime type checks. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack or gain access to sensitive information.


Affected software

jq
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Ubuntu
Basesystem Module
openEuler
Anolis OS
Fedora
LANTIME Operating System Firmware (LTOS)
jq (Ubuntu package)
jq-debugsource
jq
libjq-devel
libjq1
libjq1-debuginfo
jq-debuginfo
jq-help
jq-devel
jq-doc

How to mitigate CVE-2026-39956

Install update from vendor's website.

jq - update to 1.8.2
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
jq (Ubuntu package) - addressed in versions 1.3-1.1ubuntu1.1+esm4, 1.5+dfsg-1ubuntu0.1+esm4, 1.5+dfsg-2ubuntu0.1~esm2, 1.5+dfsg-2ubuntu0.1~esm3, 1.6-1ubuntu0.20.04.1+esm2, 1.6-1ubuntu0.20.04.1+esm3, 1.6-2.1ubuntu3.2, 1.7.1-3ubuntu0.24.04.2, 1.8.1-3ubuntu1.1, 1.8.1-4ubuntu2
jq-debugsource - update to 1.6-150000.3.20.1
jq - update to 1.6-150000.3.20.1
libjq-devel - update to 1.6-150000.3.20.1
libjq1 - update to 1.6-150000.3.20.1
libjq1-debuginfo - update to 1.6-150000.3.20.1
jq-debuginfo - update to 1.6-150000.3.20.1
jq-help - update to 1.8.0-3
jq-devel - update to 1.8.0-3
jq-debugsource - update to 1.8.0-3
jq-debuginfo - update to 1.8.0-3
jq - update to 1.8.0-3
jq - update to 1.8.1-3.fc44
jq - update to 1.8.1-4
jq-doc - update to 1.8.1-4
jq-devel - update to 1.8.1-4

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins