-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 04 Aug 2026 20:56:56 +0800 Source: jq Binary: jq jq-dbgsym libjq-dev libjq1 libjq1-dbgsym Architecture: armhf Version: 1.7.1-6+deb13u3 Distribution: trixie-security Urgency: high Maintainer: armhf Build Daemon (arm-ubc-01) Changed-By: Aron Xu Description: jq - lightweight and flexible command-line JSON processor libjq-dev - lightweight and flexible command-line JSON processor - developmen libjq1 - lightweight and flexible command-line JSON processor - shared lib Changes: jq (1.7.1-6+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Cherry-pick upstream commit for the following: CVE-2026-41256, CVE-2026-41257, CVE-2026-43896, CVE-2026-43895, CVE-2026-44777, CVE-2026-43894, CVE-2026-47770, CVE-2026-49839, CVE-2026-54679, CVE-2026-40612, GHSA-ggc9-rpv2-xgpm, GHSA-gvwx-xj9r-3frq, GHSA-gf4g-95wj-4q4r * Add missing patch for CVE-2026-32316, a prerequisite for CVE-2026-54679 fix. * Fix CVE-2024-53427 for real. The patch carried since 1.7.1-5 placed the NaN payload check inside the DEC_Conversion_syntax branch, which already returns JV_INVALID unconditionally, so it never had any effect and "NaN123" still parsed. Move the check to the decNumberIsNaN branch as upstream does, and update the two tests that encoded the old behaviour. * Do not abort when repeating a string past the length bound. The CVE-2026-32316 fix made jvp_string_append() able to return an invalid jv; binop_multiply() appended in a loop without checking, so an input like {"s":"abc","n":1000000000} with a filter of .s * .n aborted on an assertion. Reject the operation up front and stop the loop on failure. * Propagate invalid jv instead of aborting on it. The same change of contract affects jvp_string_append(), jv_string_concat() and jv_sort(); callers written against the old always-valid contract abort on an assertion. Guard centrally in jv.c so the @base64, @csv, @tsv, @sh, @uri and escape_string loops are all covered, and guard jv_delpaths(), jv_dump_string_trunc() and the jv_dump_string() results printed by main.c. delpaths and the error-message paths are regressions against previous version; the string-format ones replace the CVE-2026-32316 integer overflow with a proper error. Checksums-Sha1: 866d0c72af17cfb9e7b357099f4c04192ec4eaf8 18760 jq-dbgsym_1.7.1-6+deb13u3_armhf.deb 14b1a2af8ee48d591a732a80b0d696d1ae560205 7634 jq_1.7.1-6+deb13u3_armhf-buildd.buildinfo 1a42f630593c17e8a51e39420e5516e18b0d4e14 78892 jq_1.7.1-6+deb13u3_armhf.deb 339985744c3df5fb5cdd4d230583a71ad79ac9cc 25712 libjq-dev_1.7.1-6+deb13u3_armhf.deb 8c4b3a708bc8177548a5de19ef228f34b412f94b 377424 libjq1-dbgsym_1.7.1-6+deb13u3_armhf.deb e5ce894f4e6bbf9c08e0eb43cc66d5a44b020443 160700 libjq1_1.7.1-6+deb13u3_armhf.deb Checksums-Sha256: 058cf02a5c2a1839b7faa9bbdd29e1c4c7936826b26d76a668c7002dea492d79 18760 jq-dbgsym_1.7.1-6+deb13u3_armhf.deb 4e248064cddd642f1abcca1f5c8c7cb434ac90269122afd7a6eb726efbc72b55 7634 jq_1.7.1-6+deb13u3_armhf-buildd.buildinfo 0874a478ef5d16eb379f19415fc298603e10e16bdaa093678a396c8171e38776 78892 jq_1.7.1-6+deb13u3_armhf.deb 9d0526c441029f2f9e87a9dc7b0cceb7fe281ecf1e61687283f4e98575338732 25712 libjq-dev_1.7.1-6+deb13u3_armhf.deb 7af314baa19fe89ad793bbded9bd4de170030e60a406a2ecaf06f9a76ed1cddd 377424 libjq1-dbgsym_1.7.1-6+deb13u3_armhf.deb 5b60676b66ed61a61f88dca8bf096707621fb1f2c2c13b6c6122b93a91892a4f 160700 libjq1_1.7.1-6+deb13u3_armhf.deb Files: 5cd06e7177d7840acf87c531129bfcc9 18760 debug optional jq-dbgsym_1.7.1-6+deb13u3_armhf.deb 3f8b90a936a837b94abdac19a01ba0f4 7634 utils optional jq_1.7.1-6+deb13u3_armhf-buildd.buildinfo 60f5b81e9086ce358608a432611bdcec 78892 utils optional jq_1.7.1-6+deb13u3_armhf.deb 6ef45976191b37d1a5706698b347fc02 25712 libdevel optional libjq-dev_1.7.1-6+deb13u3_armhf.deb 37681edbb1802f7f1eb33a33d4da0049 377424 debug optional libjq1-dbgsym_1.7.1-6+deb13u3_armhf.deb c61786d822fe86a7ef2e82e50a2634c2 160700 utils optional libjq1_1.7.1-6+deb13u3_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0Ha//LlsGOpbQ/H4xqCFmsOWgoYFAmp0MLYACgkQxqCFmsOW goalTRAAlyvKrlfNk/AlVLgdg1Znt/Fzt1ksY5CCArdPKoGIkX9xf8yClGRQxJzo Q41NNVdykiGKEkTtwBAYA0kri53xfx4KpJiDKb0TRS96hbFYQg3484mJ+OMZT0ah y4U30aqB4wkHvxJ9VaWBKNfEBdOdMm5taitJnPlaDSDjaPWZC3sYf7rODOWHjwCl FEO2QZ1wF83/Hm55d4W2c3yFFHISXzltE9XU+Tk7a5Xp1DijHPr2ByFKksQzuKeQ efqfccLf1TYBBL2Uf2wGMVwo+Zg62nJlESArmMW3rVnIK22wKU5hnzb0RwwC1nXi mnWP891Do9w2NEKL7dQuuHLqxwTjVnFf3CvVhYZkJ3+wAjCZ45TLz9HGthyrhT51 Dp7YidA0CdJpTmP0ToaIzq4JG/8iyNKOAyFvN3jU54TtDfehwkldljG0qpZQ4gu3 8IZJoep4wko/o+SsX6RIxq5Ei8KL5vtnJGE7wdCf9w2wC6WOW9RYwbOXa/N68aMn nZCZDP6/a6rlrqoH9r6aOvecSXqI/AgEHXHHGM8VO7V1ml4z1RXIxrMl3LckpfkL uLDEaUaFeW3JmmmdQeMo8Ncz8u/hRXIcmZt5X3K6gOMUsOIewCLqZB74id7Qb9h5 wOSXSBc+7p4gXFzLXldALd+NJVf5xphXU43CyY2x0pElv1VEGpU= =hz77 -----END PGP SIGNATURE-----