Home / mailingsPDF  

[USN-7657-1] jq vulnerabilities

Posted on 21 July 2025
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-7657-1
July 21, 2025

jq vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 25.04
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in jq.

Software Description:
- jq: lightweight and flexible command-line JSON processor

Details:

It was discovered that jq incorrectly handled certain values when parsing
JSON data. A remote attacker could possibly use this issue to cause jq to
crash, resulting in a denial of service. (CVE-2024-23337)

It was discovered that jq incorrectly handled NaN values when parsing JSON
data. A remote attacker could possibly use this issue to cause jq to crash,
resulting in a denial of service. This issue only affected Ubuntu 24.04
LTS, and Ubuntu 25.04. (CVE-2024-53427)

It was discovered that jq incorrectly handled certain values when parsing
JSON data. A remote attacker could use this issue to cause jq to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2025-48060)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.04
jq 1.7.1-3ubuntu1.1
libjq1 1.7.1-3ubuntu1.1

Ubuntu 24.04 LTS
jq 1.7.1-3ubuntu0.24.04.1
libjq1 1.7.1-3ubuntu0.24.04.1

Ubuntu 22.04 LTS
jq 1.6-2.1ubuntu3.1
libjq1 1.6-2.1ubuntu3.1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7657-1
CVE-2024-23337, CVE-2024-53427, CVE-2025-48060

Package Information:
https://launchpad.net/ubuntu/+source/jq/1.7.1-3ubuntu1.1
https://launchpad.net/ubuntu/+source/jq/1.7.1-3ubuntu0.24.04.1
https://launchpad.net/ubuntu/+source/jq/1.6-2.1ubuntu3.1

--===============5589896839665962969==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP