-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 04 Aug 2026 20:56:56 +0800 Source: jq Binary: jq jq-dbgsym libjq-dev libjq1 libjq1-dbgsym Architecture: ppc64el Version: 1.7.1-6+deb13u3 Distribution: trixie-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-01) Changed-By: Aron Xu Description: jq - lightweight and flexible command-line JSON processor libjq-dev - lightweight and flexible command-line JSON processor - developmen libjq1 - lightweight and flexible command-line JSON processor - shared lib Changes: jq (1.7.1-6+deb13u3) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Cherry-pick upstream commit for the following: CVE-2026-41256, CVE-2026-41257, CVE-2026-43896, CVE-2026-43895, CVE-2026-44777, CVE-2026-43894, CVE-2026-47770, CVE-2026-49839, CVE-2026-54679, CVE-2026-40612, GHSA-ggc9-rpv2-xgpm, GHSA-gvwx-xj9r-3frq, GHSA-gf4g-95wj-4q4r * Add missing patch for CVE-2026-32316, a prerequisite for CVE-2026-54679 fix. * Fix CVE-2024-53427 for real. The patch carried since 1.7.1-5 placed the NaN payload check inside the DEC_Conversion_syntax branch, which already returns JV_INVALID unconditionally, so it never had any effect and "NaN123" still parsed. Move the check to the decNumberIsNaN branch as upstream does, and update the two tests that encoded the old behaviour. * Do not abort when repeating a string past the length bound. The CVE-2026-32316 fix made jvp_string_append() able to return an invalid jv; binop_multiply() appended in a loop without checking, so an input like {"s":"abc","n":1000000000} with a filter of .s * .n aborted on an assertion. Reject the operation up front and stop the loop on failure. * Propagate invalid jv instead of aborting on it. The same change of contract affects jvp_string_append(), jv_string_concat() and jv_sort(); callers written against the old always-valid contract abort on an assertion. Guard centrally in jv.c so the @base64, @csv, @tsv, @sh, @uri and escape_string loops are all covered, and guard jv_delpaths(), jv_dump_string_trunc() and the jv_dump_string() results printed by main.c. delpaths and the error-message paths are regressions against previous version; the string-format ones replace the CVE-2026-32316 integer overflow with a proper error. Checksums-Sha1: c86effe8a58cfdf247a3bd0957ee5563bbc608db 19716 jq-dbgsym_1.7.1-6+deb13u3_ppc64el.deb 7647c6eef13b137b161d6077a74c0106520ce364 7785 jq_1.7.1-6+deb13u3_ppc64el-buildd.buildinfo 593d824adc77b80bd723eec9ff5273350f979eca 79176 jq_1.7.1-6+deb13u3_ppc64el.deb e564aaa6054970961f1ff61c96774ab5f74cdc7e 25712 libjq-dev_1.7.1-6+deb13u3_ppc64el.deb f9b9af587ea616205237dbabcf4f4d60dd24a82d 397820 libjq1-dbgsym_1.7.1-6+deb13u3_ppc64el.deb 232813b19710aa98afa0b4eed79c99807d7d12d6 178520 libjq1_1.7.1-6+deb13u3_ppc64el.deb Checksums-Sha256: bad41e5aab7db85064661b248bdc8941952aade0d725e572c83fa47c4be80203 19716 jq-dbgsym_1.7.1-6+deb13u3_ppc64el.deb 9c53c37cb9f8e9fe25509a46ee3e03824e5dea19b33b2873f76d46b586b85598 7785 jq_1.7.1-6+deb13u3_ppc64el-buildd.buildinfo 4d60b36c5df3c2db9455045906b907de081d5f6fb4e84fe6ae5958f0178a7686 79176 jq_1.7.1-6+deb13u3_ppc64el.deb 04bb90ee5829346842e8aeea9197ff8cc3414650dd4b17ef96e761999b344d2a 25712 libjq-dev_1.7.1-6+deb13u3_ppc64el.deb 994b26fc06b0eb0aca9dd70baf3d3855209c7d9dc5b918d46edb7c44d1a950f0 397820 libjq1-dbgsym_1.7.1-6+deb13u3_ppc64el.deb 6c1abc10e4c6fc8e063bbbb6cfd8fd2bdf3e44ae6aabd3fed3f14001a4824cd2 178520 libjq1_1.7.1-6+deb13u3_ppc64el.deb Files: 2fe39498885c9db553f688d567ce4d99 19716 debug optional jq-dbgsym_1.7.1-6+deb13u3_ppc64el.deb 536e6a373e7d911e8eadf22a5f5f447c 7785 utils optional jq_1.7.1-6+deb13u3_ppc64el-buildd.buildinfo 43c9f1a34c31f1c282a724bc8e84768a 79176 utils optional jq_1.7.1-6+deb13u3_ppc64el.deb 9d5e57575dc048023ce1c923bdb48c1a 25712 libdevel optional libjq-dev_1.7.1-6+deb13u3_ppc64el.deb 1866916d6dce3aa20142a58baf585d36 397820 debug optional libjq1-dbgsym_1.7.1-6+deb13u3_ppc64el.deb aa13bac6f56cd63db25e4cab36babe5d 178520 utils optional libjq1_1.7.1-6+deb13u3_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEDoRc43uRWMOoIqIgDNLUPhbmg7MFAmp0MLAACgkQDNLUPhbm g7N93A//e66Y0dN3PepbCVczFqP6EZgBll7eulHhGx2vEOESVNd2KiHcTa/do41S EcxtAsbCWuDBhjuMUgpL/bQpkdtbd1Vy63b8FBDWod48J3YnV/aDgojN9onmXY+I 6JX/D6Mu/D0HKb08sRxVlTJOUDgzMUnm9Fp0YwDMhIeulWU2j83yHJni1xIt1yd0 j9kAx8AAUTBXr3gaaPqkgJtwnVUwJgs841J1VYanoe6JVCjdQFV2qvNvdi567uRz iaVgwVidTr+4/S/QBtuds4PeWN0P4DKtxb6BuzUNVxDYIeVpjY7cUSo/1eJNIPTK 5ku/baRDUN6sMyAK+xBC0fE7VbAQUK74fMpHAHqGHMBO/4MrYKnhZj0hCaxPNoHz WCLJhvI7H1fWelSrRbUIz4SmQ+/bSXvQ7DQBFOFph92wOm+T5x7Z7J1lkyY/iTmW +gzIgk130S9C+1ml+7/uluSxdjNxYL3EE16K+qMMm5S+Eu29Ou2KjqWG3pVJ197U r6w9KY7a/9HlCq295QgOu9nyduY+6bRPtsKTRTOb0kZfbjD4QHzQR630uT45hPJ9 q+7Q0dLk5lpdVhkQ+3CyZSxVR2wc6IIn7wJRNTiecD8LbtRHh+IH5Ej6jl1s0sNI H9BgMZYV8lr6f8f4geulxkzv/NJqwQlXea4sG1U7RuVlt3Q9ZeI= =HzSs -----END PGP SIGNATURE-----