CVE-2025-9403

EUVD-2025-25716
A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 11.26%
Affected Products (NVD)
VendorProductVersion
jqlangjq
𝑥
≤ 1.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jq
bookworm
unimportant
bookworm (security)
unimportant
bullseye
unimportant
bullseye (security)
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
trixie (security)
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jq
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
ignored
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
jq
suse enterprise desktop 15 SP7
1.6-150000.3.12.1
fixed
suse enterprise sap 15 SP7
1.6-150000.3.12.1
fixed
suse enterprise server 15 SP4
1.6-150000.3.12.1
fixed
suse enterprise server 15 SP7
1.6-150000.3.12.1
fixed
libjq-devel
suse enterprise desktop 15 SP7
1.6-150000.3.12.1
fixed
suse enterprise sap 15 SP7
1.6-150000.3.12.1
fixed
suse enterprise server 15 SP4
1.6-150000.3.12.1
fixed
suse enterprise server 15 SP7
1.6-150000.3.12.1
fixed
libjq1
suse enterprise desktop 15 SP7
1.6-150000.3.12.1
fixed
suse enterprise sap 15 SP7
1.6-150000.3.12.1
fixed
suse enterprise server 15 SP4
1.6-150000.3.12.1
fixed
suse enterprise server 15 SP7
1.6-150000.3.12.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
jq
Azure Linux 3.0
0:1.7.1-8.azl3
fixed
CBL-Mariner 2.0
0:1.6-5.cm2
fixed