-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 04 Aug 2026 20:56:56 +0800 Source: jq Binary: jq jq-dbgsym libjq-dev libjq1 libjq1-dbgsym Architecture: armel Version: 1.7.1-6+deb13u3 Distribution: trixie-security Urgency: high Maintainer: armel Build Daemon (arm-conova-02) Changed-By: Aron Xu Description: jq - lightweight and flexible command-line JSON processor libjq-dev - lightweight and flexible command-line JSON processor - developmen libjq1 - lightweight and flexible command-line JSON processor - shared lib Changes: jq (1.7.1-6+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Cherry-pick upstream commit for the following: CVE-2026-41256, CVE-2026-41257, CVE-2026-43896, CVE-2026-43895, CVE-2026-44777, CVE-2026-43894, CVE-2026-47770, CVE-2026-49839, CVE-2026-54679, CVE-2026-40612, GHSA-ggc9-rpv2-xgpm, GHSA-gvwx-xj9r-3frq, GHSA-gf4g-95wj-4q4r * Add missing patch for CVE-2026-32316, a prerequisite for CVE-2026-54679 fix. * Fix CVE-2024-53427 for real. The patch carried since 1.7.1-5 placed the NaN payload check inside the DEC_Conversion_syntax branch, which already returns JV_INVALID unconditionally, so it never had any effect and "NaN123" still parsed. Move the check to the decNumberIsNaN branch as upstream does, and update the two tests that encoded the old behaviour. * Do not abort when repeating a string past the length bound. The CVE-2026-32316 fix made jvp_string_append() able to return an invalid jv; binop_multiply() appended in a loop without checking, so an input like {"s":"abc","n":1000000000} with a filter of .s * .n aborted on an assertion. Reject the operation up front and stop the loop on failure. * Propagate invalid jv instead of aborting on it. The same change of contract affects jvp_string_append(), jv_string_concat() and jv_sort(); callers written against the old always-valid contract abort on an assertion. Guard centrally in jv.c so the @base64, @csv, @tsv, @sh, @uri and escape_string loops are all covered, and guard jv_delpaths(), jv_dump_string_trunc() and the jv_dump_string() results printed by main.c. delpaths and the error-message paths are regressions against previous version; the string-format ones replace the CVE-2026-32316 integer overflow with a proper error. Checksums-Sha1: 2fe9e3529185f06c5e46bce06d6e32ef2f95b34b 18564 jq-dbgsym_1.7.1-6+deb13u3_armel.deb 7fc901674b4f2d6582db0382b185e0d3de7abf7a 7620 jq_1.7.1-6+deb13u3_armel-buildd.buildinfo 267413446bb1cdafc73238490eb06c7594e74c9d 78776 jq_1.7.1-6+deb13u3_armel.deb 928407ed9d44572a3576d1be70a797a6f0f416e9 25700 libjq-dev_1.7.1-6+deb13u3_armel.deb 03153de7aae0f1c9c888740e335541eca145dab3 376432 libjq1-dbgsym_1.7.1-6+deb13u3_armel.deb b8b09be028a6b41abca8f46ae8c86771d3e5f61e 158132 libjq1_1.7.1-6+deb13u3_armel.deb Checksums-Sha256: 1429108bb7ad7f7d3371589da6d41d8a206a9955dd6c1566c9c73fe66dd4911d 18564 jq-dbgsym_1.7.1-6+deb13u3_armel.deb dc118706694f5dcf5b9386e9ad02b765911c466617ed169f1bd9b0dc32030e05 7620 jq_1.7.1-6+deb13u3_armel-buildd.buildinfo 7fecd1b1200b8c93f4118cb2a07d94b6e7412c7945a601c4827086dce3a98ea9 78776 jq_1.7.1-6+deb13u3_armel.deb 44d3f07375ea7ea286ce456c5a3225a742891ae116963f7c41e28fbb86a8172a 25700 libjq-dev_1.7.1-6+deb13u3_armel.deb 9b2fb1b07e3eacb0a024bb59ae438d888ea0549fc7f7c548cb6f72e1ee7a9b99 376432 libjq1-dbgsym_1.7.1-6+deb13u3_armel.deb ab81c16fda892f37eb8997d72093b88012ca971a23149de15f74a3517e0ab885 158132 libjq1_1.7.1-6+deb13u3_armel.deb Files: 641241b1cf907184ec65bf693e63057d 18564 debug optional jq-dbgsym_1.7.1-6+deb13u3_armel.deb 1c15b26a06e6d71ffc64dbcef99bb3d1 7620 utils optional jq_1.7.1-6+deb13u3_armel-buildd.buildinfo 7405b9c6b050de999224062346b06ed3 78776 utils optional jq_1.7.1-6+deb13u3_armel.deb a3b81f5633f954ca73f0cf57c77c522d 25700 libdevel optional libjq-dev_1.7.1-6+deb13u3_armel.deb 43e12c93fbe972bb6519402cc98cc26b 376432 debug optional libjq1-dbgsym_1.7.1-6+deb13u3_armel.deb dadbd4df1328c08947ff0fc8ea740a44 158132 utils optional libjq1_1.7.1-6+deb13u3_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEa5s+5E+WDkV2pQjwIyDMsRzdi8EFAmp0MJoACgkQIyDMsRzd i8FJmA//UmuCozIIrZ86DYJWGPjjhQwo3GoZW9bV21anK0RdwiyTPyAjygd36mTV FVFlEYcn8WVIbqeiBmjPUwHk4Z+XjjPTcbUKNigGsE6mTEofV6KPFH/F9ddpaOcY Y5SScr2+uV1s2xPyKDq0e18mZu239Ak5heGal8ggrK5jPkNjDh5nwepJvTqFUZoc FV9yaHVASjC46/xcjQsHmaxXBU7djoBtSOZZCYkg8fbZ6ePTNb3dNFE7L/GguUkz zQK4dHts0gA1n3NPC/m8SUmzxKmcgdvlcv0Fzv/QNqH9+PqkbJA6iXvw3opCGmAr C1GLmq1sffm3KwfgW7DklOowbXuEBvv7QgUU6b4RPPi57W46iiEUdcHtLzfOkRTg Tsj/oOKkD/Ab0Q3DbjwDYh5TZR2Xoc3xMT5meTMo+ru04clucIKva2d27sNe4AUd +fJWYBSCCXhY0VDpHZlN8vmnw56pvp1mZf4okyHBQWgXfEHWCkraMTifYA4ZP5a7 ZFwDsb7tG95Fz4KExqU5HLtiGRUHWwF9RL5ZNJfjkiuOdry+5HSD93El+nNpzRk7 SrMEFG0N8hQXL/CxEm5UbdC7k4IsiYpQwVMG4PjHeIHUN32khmu/OapotQrIuASM OVZWuor4YPmMKyY/XlVDwCOv7zlJSS8Zw888zoKrfJYDg8B83f8= =yEQ5 -----END PGP SIGNATURE-----