AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt)
Published May 21, 2025
7.7
HIGHCVSS 4.0
EPSS 0.53%
Description
jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_fuzz_execute harness from oss-fuzz. This crash happens on file jv.c, line 1456 `void* p = malloc(sz);`. As of time of publication, no patched versions are available.
Affected products
-
- Version <= 1.7.1StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 10
jq-0:1.7.1-8.el10_0.1
Fixed · RHSA-2025:12882
Red Hat Enterprise Linux 8
jq-0:1.6-11.el8_10
Fixed · RHSA-2025:10618
Red Hat Enterprise Linux 8.2 Advanced Update Support
jq-0:1.5-12.el8_2.1
Fixed · RHSA-2025:10622
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
jq-0:1.5-12.el8_4.4
Fixed · RHSA-2025:10621
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
jq-0:1.6-3.el8_6.1
Fixed · RHSA-2025:10620
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
jq-0:1.6-3.el8_6.1
Fixed · RHSA-2025:10620
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
jq-0:1.6-3.el8_6.1
Fixed · RHSA-2025:10620
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
jq-0:1.6-3.el8_6.1
Fixed · RHSA-2025:10620
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
jq-0:1.6-6.el8_8.3
Fixed · RHSA-2025:10619
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
jq-0:1.6-6.el8_8.3
Fixed · RHSA-2025:10619
Red Hat Enterprise Linux 9
jq-0:1.6-17.el9_6.2
Fixed · RHSA-2025:10585
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
jq-0:1.6-12.el9_0.1
Fixed · RHSA-2025:10616
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
jq-0:1.6-15.el9_2.2
Fixed · RHSA-2025:10615
Red Hat Enterprise Linux 9.4 Extended Update Support
jq-0:1.6-16.el9_4.1
Fixed · RHSA-2025:10613
Red Hat OpenShift Container Platform 4.13
rhcos-413.92.202509030117-0
Fixed · RHSA-2025:15672
Red Hat OpenShift Container Platform 4.14
rhcos-414.92.202508270040-0
Fixed · RHSA-2025:14853
Red Hat OpenShift Container Platform 4.15
rhcos-415.92.202508192014-0
Fixed · RHSA-2025:14396
Red Hat OpenShift Container Platform 4.16
rhcos-416.94.202507222002-0
Fixed · RHSA-2025:11681
Red Hat OpenShift Container Platform 4.17
rhcos-417.94.202507291008-0
Fixed · RHSA-2025:12437
Red Hat OpenShift Container Platform 4.18
rhcos-418.94.202507221927-0
Fixed · RHSA-2025:11677
Red Hat OpenShift Container Platform 4.19
rhcos-4.19.9.6.202507152218-0
Fixed · RHSA-2025:11363
Red Hat Ansible Automation Platform 2
automation-controller
Affected
Red Hat Ceph Storage 4
jq
Out of support scope
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | jq-0:1.7.1-8.el10_0.1 | Fixed | RHSA-2025:12882 |
| Red Hat Enterprise Linux 8 | jq-0:1.6-11.el8_10 | Fixed | RHSA-2025:10618 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | jq-0:1.5-12.el8_2.1 | Fixed | RHSA-2025:10622 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | jq-0:1.5-12.el8_4.4 | Fixed | RHSA-2025:10621 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | jq-0:1.6-3.el8_6.1 | Fixed | RHSA-2025:10620 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | jq-0:1.6-3.el8_6.1 | Fixed | RHSA-2025:10620 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | jq-0:1.6-3.el8_6.1 | Fixed | RHSA-2025:10620 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | jq-0:1.6-3.el8_6.1 | Fixed | RHSA-2025:10620 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | jq-0:1.6-6.el8_8.3 | Fixed | RHSA-2025:10619 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | jq-0:1.6-6.el8_8.3 | Fixed | RHSA-2025:10619 |
| Red Hat Enterprise Linux 9 | jq-0:1.6-17.el9_6.2 | Fixed | RHSA-2025:10585 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | jq-0:1.6-12.el9_0.1 | Fixed | RHSA-2025:10616 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | jq-0:1.6-15.el9_2.2 | Fixed | RHSA-2025:10615 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | jq-0:1.6-16.el9_4.1 | Fixed | RHSA-2025:10613 |
| Red Hat OpenShift Container Platform 4.13 | rhcos-413.92.202509030117-0 | Fixed | RHSA-2025:15672 |
| Red Hat OpenShift Container Platform 4.14 | rhcos-414.92.202508270040-0 | Fixed | RHSA-2025:14853 |
| Red Hat OpenShift Container Platform 4.15 | rhcos-415.92.202508192014-0 | Fixed | RHSA-2025:14396 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202507222002-0 | Fixed | RHSA-2025:11681 |
| Red Hat OpenShift Container Platform 4.17 | rhcos-417.94.202507291008-0 | Fixed | RHSA-2025:12437 |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202507221927-0 | Fixed | RHSA-2025:11677 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202507152218-0 | Fixed | RHSA-2025:11363 |
| Red Hat Ansible Automation Platform 2 | automation-controller | Affected | n/a |
| Red Hat Ceph Storage 4 | jq | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
To exploit this flaw, an attacker needs to trick a user into processing a specially crafted JSON input, allowing an attacker to trigger a buffer over-read of 2 bytes and cause a crash in jq with no other security impact. Due to these reasons, this flaw has been rated with a Moderate severity.
Red Hat mitigation
Do not process untrusted input with the jq command line JSON processor.
References (6)
- https://access.redhat.com/security/cve/CVE-2025-48060 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2367842 Issue Tracking
- https://github.com/jqlang/jq/security/advisories/GHSA-p7rr-28xf-3m5w exploitx_refsource_CONFIRMVendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/09/msg00022.html
- https://nvd.nist.gov/vuln/detail/CVE-2025-48060
- https://www.cve.org/CVERecord?id=CVE-2025-48060
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-48060 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2367842 | Issue Tracking | |
| https://github.com/jqlang/jq/security/advisories/GHSA-p7rr-28xf-3m5w | exploitx_refsource_CONFIRMVendor Advisory | |
| https://lists.debian.org/debian-lts-announce/2025/09/msg00022.html | ||
| https://nvd.nist.gov/vuln/detail/CVE-2025-48060 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-48060 |
Change history (0)
No recorded changes yet.