CVE-2026-41257

EUVD-2026-29163
jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 3.93%
Affected Products (NVD)
VendorProductVersion
jqlangjq
𝑥
≤ 1.8.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jq
bookworm
1.6-2.1+deb12u2
fixed
bookworm (security)
1.6-2.1+deb12u2
fixed
bullseye
vulnerable
bullseye (security)
1.6-2.1+deb11u3
fixed
forky
1.8.2-1
fixed
sid
1.8.2-1
fixed
trixie
vulnerable
trixie (security)
1.7.1-6+deb13u3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jq
bionic
needed
focal
needed
jammy
needed
noble
needed
questing
ignored
resolute
needed
trusty
needed
xenial
ignored
Azure Linux logo
Azure Linux Releases
Azure Package
Release
jq
Azure Linux 3.0
0:1.7.1-6.azl3
fixed