Executive brief
jq is a widely used command-line tool for processing and transforming JSON data. A vulnerability in certain versions running on 32-bit systems could allow a specially crafted JSON input to crash the application or potentially allow unauthorized code execution. This occurs because the tool incorrectly calculates memory requirements when joining large strings, leading to a memory corruption event.
Technical details
An integer overflow vulnerability exists in the `jvp_string_append` function in `src/jv.c` of jq when running on 32-bit architectures. The software attempts to prevent overflows by checking if the combined length of strings exceeds `INT_MAX`, but subsequently doubles the allocation size using 32-bit arithmetic. On 32-bit systems, the calculation `(currlen + len) * 2` can result in a value that, when passed to `jvp_string_alloc`, causes `sizeof(jvp_string) + size + 1` to wrap around `size_t`. This leads to a very small memory allocation followed by a large `memcpy` operation, resulting in a heap-based buffer overflow. An attacker providing malicious JSON input could trigger this overflow to cause a denial of service or potentially execute arbitrary code. The issue is resolved in version 1.8.2.
Affected products
- jqlang jq < 1.8.2
Timeline
- 2026-06-16: advisory: GitHub Security Advisory published
- 2026-06-25: disclosed: CVE published to NVD
- 2026-06-25: patched: Fix released in version 1.8.2