buildroot ▾
›
2025.02.x ▾
›
vulnerability
›
CVE-2026-54679
Component Overview
Vulnerability Overview
Name
CVE-2026-54679
Source
NVD (
link
)
Debian (
link
)
Description
jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun. This vulnerability is fixed in 1.8.2.
CWEs
CWE-190
Published Date
Jun 25, 2026
Updated Date
Jun 26, 2026
Workaround
-
Advisories
https://github.com/jqlang/jq/security/advisories/GHSA-29gj-222p-j7vx
Vendor Advisory
Analysis
#
Affected Component
Analysis
jq
Patched
Vulnerability Ratings
#
6.9
CVSSv4
5.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
jq
buildroot
master
1.8.2
Not Affected
jq
openwrt
master
1.8.2-r1
Not Affected
jq
openwrt
openwrt-25.12
1.8.1-r2
Exploitable
jq
yocto
kirkstone
1.6+gitX
Exploitable
jq
yocto
master
1.8.2
Not Affected
jq
yocto
scarthgap
1.7.1
Patched
Resolved with patches
#
jq (buildroot:2025.02.x)
#
Title
Author
Resolve
1
Tighten string length bounds and propagate invalid jv in
itchyny <itchyny@cybozu.co.jp>
CVE-2026-54679
jq (yocto:scarthgap)
#
Title
Author
Resolve
1
Tighten string length bounds and propagate invalid jv in
itchyny <itchyny@cybozu.co.jp>
CVE-2026-54679