-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 04 Aug 2026 20:56:56 +0800 Source: jq Binary: jq jq-dbgsym libjq-dev libjq1 libjq1-dbgsym Architecture: i386 Version: 1.7.1-6+deb13u3 Distribution: trixie-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Aron Xu Description: jq - lightweight and flexible command-line JSON processor libjq-dev - lightweight and flexible command-line JSON processor - developmen libjq1 - lightweight and flexible command-line JSON processor - shared lib Changes: jq (1.7.1-6+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Cherry-pick upstream commit for the following: CVE-2026-41256, CVE-2026-41257, CVE-2026-43896, CVE-2026-43895, CVE-2026-44777, CVE-2026-43894, CVE-2026-47770, CVE-2026-49839, CVE-2026-54679, CVE-2026-40612, GHSA-ggc9-rpv2-xgpm, GHSA-gvwx-xj9r-3frq, GHSA-gf4g-95wj-4q4r * Add missing patch for CVE-2026-32316, a prerequisite for CVE-2026-54679 fix. * Fix CVE-2024-53427 for real. The patch carried since 1.7.1-5 placed the NaN payload check inside the DEC_Conversion_syntax branch, which already returns JV_INVALID unconditionally, so it never had any effect and "NaN123" still parsed. Move the check to the decNumberIsNaN branch as upstream does, and update the two tests that encoded the old behaviour. * Do not abort when repeating a string past the length bound. The CVE-2026-32316 fix made jvp_string_append() able to return an invalid jv; binop_multiply() appended in a loop without checking, so an input like {"s":"abc","n":1000000000} with a filter of .s * .n aborted on an assertion. Reject the operation up front and stop the loop on failure. * Propagate invalid jv instead of aborting on it. The same change of contract affects jvp_string_append(), jv_string_concat() and jv_sort(); callers written against the old always-valid contract abort on an assertion. Guard centrally in jv.c so the @base64, @csv, @tsv, @sh, @uri and escape_string loops are all covered, and guard jv_delpaths(), jv_dump_string_trunc() and the jv_dump_string() results printed by main.c. delpaths and the error-message paths are regressions against previous version; the string-format ones replace the CVE-2026-32316 integer overflow with a proper error. Checksums-Sha1: f2629ef6c0dcec8af4418a70eb93f3d46b1b8132 17496 jq-dbgsym_1.7.1-6+deb13u3_i386.deb a07fc9aaa32c44ab3eb266abc2aaaf5bd5128508 7660 jq_1.7.1-6+deb13u3_i386-buildd.buildinfo b5eff3a97369017396753f390a92c865516a1aba 80396 jq_1.7.1-6+deb13u3_i386.deb f9adc6bc354e43004d685d0987fbbb568adfea04 25704 libjq-dev_1.7.1-6+deb13u3_i386.deb d69d623ddd9c6685c25c9d12dc0e9077b1a68ee5 341160 libjq1-dbgsym_1.7.1-6+deb13u3_i386.deb a59c6a6ec6852d4eac3ea1d38b5c5f394fea4076 203884 libjq1_1.7.1-6+deb13u3_i386.deb Checksums-Sha256: 910d5b478159a472dfe38841540d90b26477d4fa56181eecfabc7589d37e5f15 17496 jq-dbgsym_1.7.1-6+deb13u3_i386.deb d96b57607a93a2847d1f9a4bf79e22406227205228c154d4ae71d7cfc0d47a82 7660 jq_1.7.1-6+deb13u3_i386-buildd.buildinfo e32d3134bbc36d87a9b3e74c4dd56fa77cac5ee2aacb724a2df9ec245763a9b2 80396 jq_1.7.1-6+deb13u3_i386.deb 91eefd83071041d32676087f5f12f44e3d825d859753be10dde55e26b434ca6f 25704 libjq-dev_1.7.1-6+deb13u3_i386.deb 608bd755161665a312f1b0db08875ef29928e85df1f3e5a49398937460bbe47e 341160 libjq1-dbgsym_1.7.1-6+deb13u3_i386.deb 2a7631dca1a837d73b5005d4adf14730b74c96b3694709f5709d79f2544b94d1 203884 libjq1_1.7.1-6+deb13u3_i386.deb Files: ff657fb4b2ade6f983949f7dba15171c 17496 debug optional jq-dbgsym_1.7.1-6+deb13u3_i386.deb f78197d8a7baa6fcad2b043ad58e593c 7660 utils optional jq_1.7.1-6+deb13u3_i386-buildd.buildinfo f345bb83e282885641495cac312f3dcf 80396 utils optional jq_1.7.1-6+deb13u3_i386.deb 65dcc9dee7572d1be085c6cf442c28ce 25704 libdevel optional libjq-dev_1.7.1-6+deb13u3_i386.deb 87c2dd63ded8dbb3e148c9794b46c852 341160 debug optional libjq1-dbgsym_1.7.1-6+deb13u3_i386.deb 6cbb80da76e8ba2da253f43ca78096d5 203884 utils optional libjq1_1.7.1-6+deb13u3_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBDWXQb2umOtH4DRpYg9P9sm2dfEFAmp0MMsACgkQYg9P9sm2 dfErEQ/+MI2kfahdG0cmYOB3lmJYKw43TRyjwTocA6tXyarbefZTOe7KRVQnlVWO YvqeyhL0Uo+0ObmzKadMmX8/4VOIxr/t+DqGapNq1Mp/15nMpiKaHVPkSkLocTYG OO3JaCpaTwFOYPiqJ8GWqJ53uOBEyvi6RMba2Ww1bv1EUDv4yv4zpGg2VC8DwkQY LM4CtEfT9lKORnIUx80LmH/yqgP7uwzEc50W70zmE1cyY00PGgqWysUHNztmbOak a4hmAQJ2RvyFOrixBNCllU5DVcEkNpn2KM7tusowRa/iEyQeLsyZ9s77IywPt1+0 xCkRNeznFHRFCwvXn1wP8W5by44YqYevSSYfi2JRAGliA3Is2hGhv7hzYANGnjZZ 5zJJfmcPjre1GFzbnyOzpWZKrjdZOaFBPolTwzuFAuFCHEyczrHL2KeJ+Zuiw1MW DLbRaYoq+XzxeR6T2Ej1jbxKFAK0VP8HX0BH49qlaV+4WFAYbueaj7E9rZCAqts0 AbfR5H3ZWpSF0E8rH8Dt8gtpc6v8qr2xTcNcdbFiTx/TpXLVf+GpLauGPDC7pK3a IFpf3UQ/2mVRA5A2qh0wFDf5fYoBs2bj/7z/r4ELGOSyv70LmD6X7L72pbNjcFsK 4eYRAj+Up/wlkDn585xy8Ltn5g+UbC0a54N2OM3ORYjqRWqdt1E= =3GDm -----END PGP SIGNATURE-----