-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 04 Aug 2026 20:56:56 +0800 Source: jq Binary: jq jq-dbgsym libjq-dev libjq1 libjq1-dbgsym Architecture: arm64 Version: 1.7.1-6+deb13u3 Distribution: trixie-security Urgency: high Maintainer: arm64 Build Daemon (arm-ubc-02) Changed-By: Aron Xu Description: jq - lightweight and flexible command-line JSON processor libjq-dev - lightweight and flexible command-line JSON processor - developmen libjq1 - lightweight and flexible command-line JSON processor - shared lib Changes: jq (1.7.1-6+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Cherry-pick upstream commit for the following: CVE-2026-41256, CVE-2026-41257, CVE-2026-43896, CVE-2026-43895, CVE-2026-44777, CVE-2026-43894, CVE-2026-47770, CVE-2026-49839, CVE-2026-54679, CVE-2026-40612, GHSA-ggc9-rpv2-xgpm, GHSA-gvwx-xj9r-3frq, GHSA-gf4g-95wj-4q4r * Add missing patch for CVE-2026-32316, a prerequisite for CVE-2026-54679 fix. * Fix CVE-2024-53427 for real. The patch carried since 1.7.1-5 placed the NaN payload check inside the DEC_Conversion_syntax branch, which already returns JV_INVALID unconditionally, so it never had any effect and "NaN123" still parsed. Move the check to the decNumberIsNaN branch as upstream does, and update the two tests that encoded the old behaviour. * Do not abort when repeating a string past the length bound. The CVE-2026-32316 fix made jvp_string_append() able to return an invalid jv; binop_multiply() appended in a loop without checking, so an input like {"s":"abc","n":1000000000} with a filter of .s * .n aborted on an assertion. Reject the operation up front and stop the loop on failure. * Propagate invalid jv instead of aborting on it. The same change of contract affects jvp_string_append(), jv_string_concat() and jv_sort(); callers written against the old always-valid contract abort on an assertion. Guard centrally in jv.c so the @base64, @csv, @tsv, @sh, @uri and escape_string loops are all covered, and guard jv_delpaths(), jv_dump_string_trunc() and the jv_dump_string() results printed by main.c. delpaths and the error-message paths are regressions against previous version; the string-format ones replace the CVE-2026-32316 integer overflow with a proper error. Checksums-Sha1: b0dade9c65c2c8c0a8b09fab769032985970a9d4 19416 jq-dbgsym_1.7.1-6+deb13u3_arm64.deb 364805a8a6a4f981a699b37d650a8cc6f1e14ebb 7752 jq_1.7.1-6+deb13u3_arm64-buildd.buildinfo d352ec4c6ad49118a89af1f480fb1112c6df9589 78328 jq_1.7.1-6+deb13u3_arm64.deb d8022af9f9c9e9b3a65682fb5961f6bed8c267b7 25700 libjq-dev_1.7.1-6+deb13u3_arm64.deb 8914f40d950419192732c3c53b8495921a12d20d 377800 libjq1-dbgsym_1.7.1-6+deb13u3_arm64.deb b175548bde68584747c65be140eb3f742d6fdfba 151612 libjq1_1.7.1-6+deb13u3_arm64.deb Checksums-Sha256: c96dccbab42490c96fac48b3e5b11759a942075b1dcef3566e887e276681251a 19416 jq-dbgsym_1.7.1-6+deb13u3_arm64.deb 004657efc3e719f1c7f162a4a9d9dce2e8a216ac849883dfd25658a4a9c7bead 7752 jq_1.7.1-6+deb13u3_arm64-buildd.buildinfo d35bc9f804784d39e7b89e63314a80f113d8a7ccbeb36cf0d3cc01c3a65312e2 78328 jq_1.7.1-6+deb13u3_arm64.deb 0ced8f3d70722a5f5bb7763419f36f62036c34ad19885314d3203ccf818ce0a4 25700 libjq-dev_1.7.1-6+deb13u3_arm64.deb 48a520d95b053cd072c70f0114d8dd996666be77cd33c15f67db0930e7cbd763 377800 libjq1-dbgsym_1.7.1-6+deb13u3_arm64.deb b8bf914f7106442f4a42db26867750b7fe031d11b2abff944822872386371ddf 151612 libjq1_1.7.1-6+deb13u3_arm64.deb Files: e3b190e14f430cccc986b6eb5c7733ac 19416 debug optional jq-dbgsym_1.7.1-6+deb13u3_arm64.deb 88cfb65fd5968e796794790f71591076 7752 utils optional jq_1.7.1-6+deb13u3_arm64-buildd.buildinfo 5c0fae4a28863081b2a3e5c157db2238 78328 utils optional jq_1.7.1-6+deb13u3_arm64.deb 70492ad5ef1573b8d2e0f313a52adf87 25700 libdevel optional libjq-dev_1.7.1-6+deb13u3_arm64.deb 94d5344b4fa2b84e202f0af6542f051e 377800 debug optional libjq1-dbgsym_1.7.1-6+deb13u3_arm64.deb cd8ff020372c324cc1bd52f1bd0c102e 151612 utils optional libjq1_1.7.1-6+deb13u3_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEJkN0BnKzGWWW6tS+G5VHrWJmwgcFAmp0MJYACgkQG5VHrWJm wgffyBAApDWzdZ3mTF3OGuZtBTiSlrIEoAcEoJj1tpvSjIYcGpv+2XBMYOXKfgAO +gPO0BBjL0eqAGSOW7Y+7OobRclW3KCls1/VOcFZti82fqlvVY8f+f9ZaQrWzAsS qEgLkaVx4NXfzIQ6du65KmV1Ac2ytZ5Pb/CXA18hUrKJsXDFCoOVhrCEBFywZV/s 7S1clpnUQTIed/JPWMCf/uoJEe9S/ztDVDyhCMoO7EON6KdJLdu3Ns57H/3sF2FU epJl+3cJ3MjnvPTCPyLjl/ZGIz07nZXI4YlqBaupDEEiTpujKLpy7EAX+6Xj0Wyo TDBXkz64HH7eFkuADRHRjxuQ4tTfRh5E9Z56OCi8AC+0lUUbDZtajUzYaZ5ARCyu 7Zme0blgUK3k3AGNhk+MmP2kXo5oUVO7lxGCIuav5YjuX21NODuVeQSpOYGQ8NSI rCkjlG5cHxCNFUK77uv+mpHCjLticxrJy1eJVmtNleYIhYy90+smXSy//uMZ2EYu ajM+X5a0lFQ/xoz4Hy7gf2qSz+SRESS3zFyKU2qQV1shtrbs+YLtqbQ6r4YKXd6Y ae90PHPes/mIrSMaWc8B4pCU2Cxno9+fHauAUKnELlAHZlBK7GOzWXR5XF9YIxkf QGmLhdm5+XnjwaZilrGlFBo71EX4Y+V2fQCXSBoLlQ/VnlLrHRo= =6nfb -----END PGP SIGNATURE-----