PT-2026-52519 · Jq · Jq
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
jq versions prior to 1.8.2
Description
On 32-bit systems, the
jvp string append() function is susceptible to integer or multiplication overflow, which can lead to a significant buffer overrun. A buffer overrun occurs when a program writes more data to a block of memory than it is allocated to hold, potentially corrupting adjacent memory.Recommendations
Update to version 1.8.2.
Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jq