Back Linuxsecurity Ubuntu 26.04 LTS jq Important DoS and Code Exec Issues USN-8202
A security issue affects these releases of Ubuntu and its derivatives: Summary: Several security issues were fixed in jq. Software Description: Details: USN-8202-1 fixed vulnerabilities in jq. This update provides the corresponding update to Ubuntu 26.04 LTS. Original advisory details: It was discovered that jq did not correctly handle certain string concatenations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-32316) It was discovered that jq did not correctly handle recursion in certain circumstances. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-33947) It was discovered that jq did not correctly handle improperly terminated strings. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-33948) It was discovered that jq did not correctly handle checking certain
A security issue affects these releases of Ubuntu and its derivatives: Summary: Several security issues were fixed in jq. Software Description: Details: USN-8202-1 fixed vulnerabilities in jq. This update provides the corresponding update to Ubuntu 26.04 LTS. Original advisory details: It was discovered that jq did not correctly handle certain string concatenations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-32316) It was discovered that jq did not correctly handle recursion in certain circumstances. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-33947) It was discovered that jq did not correctly handle improperly terminated strings. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-33948) It was discovered that jq did not correctly handle checking certain
The problem can be corrected by updating your system to the following package versions: In general, a standard system update will make all the necessary changes.
The problem can be corrected by updating your system to the following package versions: In general, a standard system update will make all the necessary changes.
CVE-2026-32316, CVE-2026-33947, CVE-2026-33948, CVE-2026-39956, CVE-2026-39979, CVE-2026-40164
CVE-2026-32316, CVE-2026-33947, CVE-2026-33948, CVE-2026-39956,
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
