Logo
vulnerabilityCVE-2026-39956
Name
CVE-2026-39956
Source
NVD ( link)Debian ( link)
Description
jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relies solely on assert() checks that are stripped in release builds compiled with -DNDEBUG. This allows an attacker to crash jq trivially with input like _strindices(0), and by crafting a numeric value whose IEEE-754 bit pattern maps to a chosen pointer, achieve a controlled pointer dereference and limited memory read/probe primitive. Any deployment that evaluates untrusted jq filters against a release build is vulnerable. This issue has been patched in commit fdf8ef0f0810e3d365cdd5160de43db46f57ed03.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
jq
Patched

Vulnerability Ratings#


6.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.7.1
Not Affected
buildroot
master
1.8.2
Not Affected
openwrt
master
1.8.2-r1
Not Affected
openwrt
openwrt-25.12
1.8.1-r2
Not Affected
yocto
kirkstone
1.6+gitX
Not Affected
yocto
master
1.8.2
Not Affected

Resolved with patches#


jq (yocto:scarthgap)

#
Title
Author
Resolve
1
Add runtime type checks to f_string_indexes
tlsbollei <170938166+tlsbollei@users.noreply.github.com>
CVE-2026-39956