-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 04 Aug 2026 20:56:56 +0800 Source: jq Binary: jq jq-dbgsym libjq-dev libjq1 libjq1-dbgsym Architecture: riscv64 Version: 1.7.1-6+deb13u3 Distribution: trixie-security Urgency: high Maintainer: riscv64 Build Daemon (rv-manda-02) Changed-By: Aron Xu Description: jq - lightweight and flexible command-line JSON processor libjq-dev - lightweight and flexible command-line JSON processor - developmen libjq1 - lightweight and flexible command-line JSON processor - shared lib Changes: jq (1.7.1-6+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Cherry-pick upstream commit for the following: CVE-2026-41256, CVE-2026-41257, CVE-2026-43896, CVE-2026-43895, CVE-2026-44777, CVE-2026-43894, CVE-2026-47770, CVE-2026-49839, CVE-2026-54679, CVE-2026-40612, GHSA-ggc9-rpv2-xgpm, GHSA-gvwx-xj9r-3frq, GHSA-gf4g-95wj-4q4r * Add missing patch for CVE-2026-32316, a prerequisite for CVE-2026-54679 fix. * Fix CVE-2024-53427 for real. The patch carried since 1.7.1-5 placed the NaN payload check inside the DEC_Conversion_syntax branch, which already returns JV_INVALID unconditionally, so it never had any effect and "NaN123" still parsed. Move the check to the decNumberIsNaN branch as upstream does, and update the two tests that encoded the old behaviour. * Do not abort when repeating a string past the length bound. The CVE-2026-32316 fix made jvp_string_append() able to return an invalid jv; binop_multiply() appended in a loop without checking, so an input like {"s":"abc","n":1000000000} with a filter of .s * .n aborted on an assertion. Reject the operation up front and stop the loop on failure. * Propagate invalid jv instead of aborting on it. The same change of contract affects jvp_string_append(), jv_string_concat() and jv_sort(); callers written against the old always-valid contract abort on an assertion. Guard centrally in jv.c so the @base64, @csv, @tsv, @sh, @uri and escape_string loops are all covered, and guard jv_delpaths(), jv_dump_string_trunc() and the jv_dump_string() results printed by main.c. delpaths and the error-message paths are regressions against previous version; the string-format ones replace the CVE-2026-32316 integer overflow with a proper error. Checksums-Sha1: ea30acd8b6b92bedffd63e1b88a08e58ff4a919d 18672 jq-dbgsym_1.7.1-6+deb13u3_riscv64.deb 500297bf08aa416eb4e084d81035a2a1a0fcd9da 7730 jq_1.7.1-6+deb13u3_riscv64-buildd.buildinfo 16768912f678a72a300507e81dc7425756b10dbc 78600 jq_1.7.1-6+deb13u3_riscv64.deb 153d2c5486e8e752d7d64e4358061e17499b98da 25700 libjq-dev_1.7.1-6+deb13u3_riscv64.deb 849a65eab9d8d97c749a7bb040ecfe8abd0ed861 355480 libjq1-dbgsym_1.7.1-6+deb13u3_riscv64.deb 11167a1d201ba8091fe845c0993a45725f361101 168912 libjq1_1.7.1-6+deb13u3_riscv64.deb Checksums-Sha256: 8c85b03036f89b24c0380bbe932c0fac0c0c371b60d9b4f6c7b072eb6c01c457 18672 jq-dbgsym_1.7.1-6+deb13u3_riscv64.deb d0a94020bcc0a5912838cbe4fd169ff53e48291717d6eaada74158ddfe8acda6 7730 jq_1.7.1-6+deb13u3_riscv64-buildd.buildinfo 141906dbf8ceb7db14dd753d3ede08d273b95e96ed9701b39f0b1e402150d3a7 78600 jq_1.7.1-6+deb13u3_riscv64.deb 87f66f135b4ecc63d6ab52087227798b0d92d032bce87106bec611fdc5f626c7 25700 libjq-dev_1.7.1-6+deb13u3_riscv64.deb 55505650769f9762c5c911880b98041274e3dfe5eceb5b06c75850a9455b1327 355480 libjq1-dbgsym_1.7.1-6+deb13u3_riscv64.deb 99e47f4a2841dbd522c5eee82fe6d99afc2d5ac5d5bad599e486990b21c674ea 168912 libjq1_1.7.1-6+deb13u3_riscv64.deb Files: 939ce4836c814eae420ca22c311ad6e5 18672 debug optional jq-dbgsym_1.7.1-6+deb13u3_riscv64.deb 3a170c0f5bf2b6d122e3b97f974fced7 7730 utils optional jq_1.7.1-6+deb13u3_riscv64-buildd.buildinfo b9ffdd2966b0b09b578b6cfa1af7c08e 78600 utils optional jq_1.7.1-6+deb13u3_riscv64.deb 4209fc3eb4651af496674a3f3832a974 25700 libdevel optional libjq-dev_1.7.1-6+deb13u3_riscv64.deb 5d3155f959e424e9b09938374d988800 355480 debug optional libjq1-dbgsym_1.7.1-6+deb13u3_riscv64.deb 5e0b2af0c47521cc343b13743abe4a6f 168912 utils optional libjq1_1.7.1-6+deb13u3_riscv64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEER+evXFzNzDWbUDPF7SlJcp2g6OIFAmp0MesACgkQ7SlJcp2g 6OLJYg//c/SNUji3RwCoySxKvujK2Whb2bjIFGveYkT2xlNcyeCrd31F/ubMk/EK FTIro2MKGw0jiZQwHWyU/5OWiN6Ia5ILARIRaOwrHCnoerOLJ5x3ro9b1/Z18tB/ ppdGyPcg9ec2eRXHhKnichY6zz5cBQHV93oJ1hrcA06NthKYmld4W+VHFJDeaAZs t1TZAK0WMo4JMlM5A8YOm/NuKPPXxsWRzGxyxdfkQz6pK/EnM5ZrsiPdOU49WXPf 9lZXnJdJwvXnhMvn8iE8vfcAtvB9gYvV0KVeyjdz2EnYAXiipfgPyYf51dj3lUSK vCAlIDKbkpBssfTMbL4UN5osiWTFF6m5clVrtmtTLAPlgDFAJz6DFGzd0agLmUJ3 NOUV1axWfpZ/1J8BhjxMXWEDyboOhQWVuEwM+Z8EWa85G+9XUIeZZ0eyMcIVgoi+ kHRCXopIoq2WKo/WXEppDVj5/5lXwWFuDVycGVbZvZjYj5ctfFZQGSRNMiTfCbtc jhclpd9sNBz7Ze8a15fYFsljO4RMwwU/Ogmqa8NEhUUHgYUIjI3rfwH48Vztgent g81SQaGknAHRc6Qr0oqB2dxUqv4h6Yke6uAGmBsGovYUcCh97vlOFFkw5V+CRWSE +p19MsZ0MkR/vJi7iWikMTAMro6i03rBq+yTheSGiwC3v8SxRR4= =wzou -----END PGP SIGNATURE-----