-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 04 Aug 2026 20:56:56 +0800 Source: jq Binary: jq jq-dbgsym libjq-dev libjq1 libjq1-dbgsym Architecture: amd64 Version: 1.7.1-6+deb13u3 Distribution: trixie-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Aron Xu Description: jq - lightweight and flexible command-line JSON processor libjq-dev - lightweight and flexible command-line JSON processor - developmen libjq1 - lightweight and flexible command-line JSON processor - shared lib Changes: jq (1.7.1-6+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Cherry-pick upstream commit for the following: CVE-2026-41256, CVE-2026-41257, CVE-2026-43896, CVE-2026-43895, CVE-2026-44777, CVE-2026-43894, CVE-2026-47770, CVE-2026-49839, CVE-2026-54679, CVE-2026-40612, GHSA-ggc9-rpv2-xgpm, GHSA-gvwx-xj9r-3frq, GHSA-gf4g-95wj-4q4r * Add missing patch for CVE-2026-32316, a prerequisite for CVE-2026-54679 fix. * Fix CVE-2024-53427 for real. The patch carried since 1.7.1-5 placed the NaN payload check inside the DEC_Conversion_syntax branch, which already returns JV_INVALID unconditionally, so it never had any effect and "NaN123" still parsed. Move the check to the decNumberIsNaN branch as upstream does, and update the two tests that encoded the old behaviour. * Do not abort when repeating a string past the length bound. The CVE-2026-32316 fix made jvp_string_append() able to return an invalid jv; binop_multiply() appended in a loop without checking, so an input like {"s":"abc","n":1000000000} with a filter of .s * .n aborted on an assertion. Reject the operation up front and stop the loop on failure. * Propagate invalid jv instead of aborting on it. The same change of contract affects jvp_string_append(), jv_string_concat() and jv_sort(); callers written against the old always-valid contract abort on an assertion. Guard centrally in jv.c so the @base64, @csv, @tsv, @sh, @uri and escape_string loops are all covered, and guard jv_delpaths(), jv_dump_string_trunc() and the jv_dump_string() results printed by main.c. delpaths and the error-message paths are regressions against previous version; the string-format ones replace the CVE-2026-32316 integer overflow with a proper error. Checksums-Sha1: 4d0f42be56fe82d2269b7eb3ba8f515f6a58f09d 19096 jq-dbgsym_1.7.1-6+deb13u3_amd64.deb 441747206a0d0c78db8aefe96fbfe40e1bc52bdc 7826 jq_1.7.1-6+deb13u3_amd64-buildd.buildinfo 319826865114024846a4efa2ba8599934110f5ae 78792 jq_1.7.1-6+deb13u3_amd64.deb 9a40516e73c8b7dec78b9c9910d4b9ebb5a17b7b 25712 libjq-dev_1.7.1-6+deb13u3_amd64.deb 9448ebe952b481e5eddf73eb6d320cf84996f1fb 396808 libjq1-dbgsym_1.7.1-6+deb13u3_amd64.deb 8f552251072a73c57a210b45a06c3f8914270747 167952 libjq1_1.7.1-6+deb13u3_amd64.deb Checksums-Sha256: 7d2d3c1c3f243a3bfe8a2cdf9672df93842cf0edd42ada58ec61d964bc67a1ac 19096 jq-dbgsym_1.7.1-6+deb13u3_amd64.deb 7e5e3cc3abf19619fc9fee42dc074cce6b9af1f59d93656bf4a73823ac3d42be 7826 jq_1.7.1-6+deb13u3_amd64-buildd.buildinfo 4415dc18d4ea29d8e12d410dd8c71c567d44d8ec5e24afaed3aa7a149b063643 78792 jq_1.7.1-6+deb13u3_amd64.deb 4aeef8ad9aefd49aaa92f8f327094039c0c20875d7c49b0164f34398e3a51bb8 25712 libjq-dev_1.7.1-6+deb13u3_amd64.deb b00c5a654512cc82baba85819f2a5583a3036ca4494a83ea8f81830e58deda94 396808 libjq1-dbgsym_1.7.1-6+deb13u3_amd64.deb 62444043e4b8f21a5154e5b7084d85db00da509e163c52a950bb8aeb75e4012e 167952 libjq1_1.7.1-6+deb13u3_amd64.deb Files: fe808e713592d11c8e2cf4c8947ec341 19096 debug optional jq-dbgsym_1.7.1-6+deb13u3_amd64.deb 5b073b55ec584034e5ff899fcb2d889b 7826 utils optional jq_1.7.1-6+deb13u3_amd64-buildd.buildinfo 171d30d8b0ab8d9d4a4abc9842708238 78792 utils optional jq_1.7.1-6+deb13u3_amd64.deb 84f678c3e189bacc951614a8d82ea6c8 25712 libdevel optional libjq-dev_1.7.1-6+deb13u3_amd64.deb 8f60cc4553afca814ffd51f0943e667f 396808 debug optional libjq1-dbgsym_1.7.1-6+deb13u3_amd64.deb 18ccb89299b075ab72607c7efd520854 167952 utils optional libjq1_1.7.1-6+deb13u3_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmp0MQsACgkQTwt/65ON 6zdbvQ//adgZlYyXnya7VK60tyeiExa7rZ/0Sis/TLMiqGbdah3/b6XoweDbNGcL NBHDcb8B5i3w0wfxxsnqRzCopl6NaZ9RPnHeFd3Zrerr5pFtadh+ZyjoYj8PxQBR a2SXVWO7lhoabjVUYAyV+D5xxpXq0hLmvAG5dmv2EQ/aubKSqb2zLnxTgLcejbv3 pvdaDu4+PKtvRszheMxiW0Tvgzca1murJ0cmS5BgZyUR2DgqBCzMXzX4lPYk1uSF /D8RrH1floe8wA3bXLhAoVnWaSd1TPjMWcCH+dUFc02b2hEoVsN3XIoCebMH9zUc ZwEqBFp6IIMO0fFnQvR3jBE3XbNa/EH5nVj5OvOgFwnEhyMnyRt31TwflayLUSdA tEKXsc/40nV1ZyQSpKWVbdC4DEJvdFCdoQ96TmxiAzkga4Gao+F5nguvXr1DsIwL y8nNDq0pAJaxMGWQzPOHR46UAKUItYnR1g9imGZOax50iSGOJukCGkwnHtRcIfHl XOaXLECWplKYJumYkwa9nP13co/n8BCgsGnWMbeoPdNiFRQKXuSgOXk5H+9q5q8r p6MScjE54O3DSn2a2RWHw/Ac+Uxt0cEbuuub0EsZ6rnrXEsxh63u6gl6I154aNiJ 2jvrUzCF4Q/hj8OGuaJ50PT+VkbX4ee/G6JOzrc/O71ap2gig6U= =48TA -----END PGP SIGNATURE-----