Multiple jq Vulnerabilities in Ubuntu 26.04 LTS Lead to DoS and Code Execution Risks

Multiple jq Vulnerabilities in Ubuntu 26.04 LTS Lead to DoS and Code Execution Risks

First seen 28 Apr 2026, 11:33 UTC UbuntuLinuxsecurity 94% similarity 57.8

Article Content

Browse articles
ThreatCluster

On April 28, 2026, Ubuntu released USN-8202-2 addressing several vulnerabilities in jq, a command-line JSON processor. These vulnerabilities include improper handling of string concatenations (CVE-2026-32316), recursion (CVE-2026-33947), improperly terminated strings (CVE-2026-33948), and variable type checking (CVE-2026-39956). Attackers could exploit these issues to cause denial of service or execute arbitrary code. The vulnerabilities were published on April 13, 2026, and affect Ubuntu 26.04 LTS and its derivatives. Users are advised to update their systems to mitigate these risks. The vulnerabilities could potentially lead to sensitive information leaks or service disruptions. The patch is available as part of a standard system update.

Key Points: • Multiple vulnerabilities in jq could lead to denial of service or arbitrary code execution. • Affected versions include Ubuntu 26.04 LTS and its derivatives. • Users should update their systems to the latest package versions to mitigate risks.

ThreatCluster AI

Timeline

2026-04-13
CVE-2026-32316, CVE-2026-33947, CVE-2026-33948, CVE-2026-39956 published
2026-04-13
CVE-2026-40164 published
2026-04-13
CVE-2026-39979 published
2026-04-28
USN-8202-2 released to address jq vulnerabilities

Community

Browse all →

Tracked Entities in This Story