[CLSA-2026:1787781806] jq: Fix of CVE-2026-39956
Type:
security
Severity:
Moderate
Release date:
2026-08-26 22:04:01 UTC
Description:
- CVE-2026-39956: add runtime type checks to the _strindices builtin to prevent a crash and limited memory disclosure on non-string arguments
CVEs fixed:
Updated packages:
  • jq-1.6-14.el9_2.tuxcare.els10.i686.rpm
    sha:940fe93f1515c233d4fdc1d714f184fd96ee2c965cd0b14cf6c4843cd4f7a2ab
  • jq-1.6-14.el9_2.tuxcare.els10.x86_64.rpm
    sha:2de2f1f769252fe7a10365b84caba9c93798d568e3bf2c8b2808a5f870c1bb4f
  • jq-devel-1.6-14.el9_2.tuxcare.els10.i686.rpm
    sha:2eaf7723a0f82d47c4cf20b484e329ed99946be34098501eed59f41134782c92
  • jq-devel-1.6-14.el9_2.tuxcare.els10.x86_64.rpm
    sha:61f1beaf8842ec6d593071108feaabed0cc39f9319061835e3b370679c4665f5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.