jq heap use after free vulnerability in f_strflocaltime
Published Jun 19, 2025
5.5
MEDIUMCVSS 4.0
EPSS 0.37%
Description
jq is a command-line JSON processor. In version 1.8.0 a heap use after free vulnerability exists within the function f_strflocaltime of /src/builtin.c. This issue has been patched in commit 499c91b, no known fix version exists at time of publication.
Affected products
-
- Version = 1.8.0StatusaffectedConstraints-
- Version
No data.
No data.
Red Hat Ansible Automation Platform 2
automation-controller
Fix deferred
Red Hat Ceph Storage 4
jq
Not affected
Red Hat Enterprise Linux 10
jq
Not affected
Red Hat Enterprise Linux 8
jq
Not affected
Red Hat Enterprise Linux 9
jq
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
Red Hat Trusted Application Pipeline
rhtap-cli/rhtap-cli-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2 | automation-controller | Fix deferred | n/a |
| Red Hat Ceph Storage 4 | jq | Not affected | n/a |
| Red Hat Enterprise Linux 10 | jq | Not affected | n/a |
| Red Hat Enterprise Linux 8 | jq | Not affected | n/a |
| Red Hat Enterprise Linux 9 | jq | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
| Red Hat Trusted Application Pipeline | rhtap-cli/rhtap-cli-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2025-49014 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2373892 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-18920 Advisory
- https://github.com/jqlang/jq/commit/499c91bca9d4d027833bc62787d1bb075c03680e x_refsource_MISC
- https://github.com/jqlang/jq/security/advisories/GHSA-rmjp-cr27-wpg2 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2025-49014
- https://www.cve.org/CVERecord?id=CVE-2025-49014
Change history (0)
No recorded changes yet.