------------------------------------------------------------------------- Debian LTS Advisory DLA-4661-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Andreas Henriksson July 01, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : jq Version : 1.6-2.1+deb11u3 CVE ID : CVE-2026-43894 CVE-2026-47770 CVE-2026-49839 CVE-2026-54679 Debian Bug : 1136445 It was found that jq, a lightweight and flexible command-line JSON parser, was vulnerable to multiple memory corruption attacks, which could lead to application crashes, denial-of-service conditions, and potentially arbitrary code execution through heap corruption when parsing untrusted input. For Debian 11 bullseye, these problems have been fixed in version 1.6-2.1+deb11u3. We recommend that you upgrade your jq packages. For the detailed security status of jq please refer to its security tracker page at: https://security-tracker.debian.org/tracker/jq Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment:
signature.asc
Description: PGP signature