Back

HIGH

AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt)

Published May 21, 2025

Description

jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_fuzz_execute harness from oss-fuzz. This crash happens on file jv.c, line 1456 `void* p = malloc(sz);`. As of time of publication, no patched versions are available.

Affected products

Remediation

Red Hat statement

To exploit this flaw, an attacker needs to trick a user into processing a specially crafted JSON input, allowing an attacker to trigger a buffer over-read of 2 bytes and cause a crash in jq with no other security impact. Due to these reasons, this flaw has been rated with a Moderate severity.

Red Hat mitigation

Do not process untrusted input with the jq command line JSON processor.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 21, 2025
Updated Nov 3, 2025
Reserved May 15, 2025
CISA Vulnrichment
Updated May 21, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 21, 2025