{"id":"CVE-2026-39979","summary":"jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers","details":"jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL terminator is found rather than respecting the caller-supplied length. This means that when malformed JSON is passed in a non-NUL-terminated buffer, the error construction logic performs an out-of-bounds read past the end of the buffer. The vulnerability is reachable by any libjq consumer calling jv_parse_sized() with untrusted input, and depending on memory layout, can result in memory disclosure or process termination. The issue has been patched in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f.","aliases":["GHSA-2hhh-px8h-355p"],"modified":"2026-07-22T04:28:27.292339Z","published":"2026-04-13T22:18:56.252Z","related":["ALSA-2026:16252","ALSA-2026:16692","ALSA-2026:16693","ALSA-2026:19151","ALSA-2026:19365","SUSE-SU-2026:22545-1","SUSE-SU-2026:22566-1","SUSE-SU-2026:22664-1","SUSE-SU-2026:2983-1","openSUSE-SU-2026:10850-1","openSUSE-SU-2026:21248-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39979.json","unresolved_ranges":[{"extracted_events":[{"fixed":"2f09060afab23fe9390cce7cb860b10416e1bf5f"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"fixed":"2f09060afab23fe9390cce7cb860b10416e1bf5f"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39979.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16252"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16692"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:16693"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18040"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18042"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18043"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18044"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18045"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18046"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18047"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18048"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19151"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19365"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:23233"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:23245"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:25044"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:25096"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:25181"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:26528"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:26542"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:28887"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30078"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30087"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30088"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:30089"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:34098"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:8579"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-39979"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39979.json"},{"type":"ADVISORY","url":"https://github.com/jqlang/jq/security/advisories/GHSA-2hhh-px8h-355p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39979"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2458077"},{"type":"FIX","url":"https://github.com/jqlang/jq/commit/2f09060afab23fe9390cce7cb860b10416e1bf5f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jqlang/jq","events":[{"introduced":"0"},{"fixed":"2f09060afab23fe9390cce7cb860b10416e1bf5f"}],"database_specific":{"source":"REFERENCES"}}],"versions":["jq-1.8.1","jq-1.8.0","jq-1.7.1","jq-1.7","jq-1.7rc2","jq-1.7rc1","jq-1.6","1.6rc2","jq-1.6rc1","jq-1.5rc2","jq-1.5rc1","jq-1.4","jq-1.3","jq-1.2","jq-1.1","jq-1.0"],"database_specific":{"vanir_signatures_modified":"2026-07-22T04:28:27Z","vanir_signatures":[{"target":{"file":"src/jv_parse.c","function":"jv_parse_sized_custom_flags"},"deprecated":false,"digest":{"function_hash":"199510934960573295006688652191971625366","length":846},"id":"CVE-2026-39979-05ddb4a8","signature_type":"Function","signature_version":"v1","source":"https://github.com/jqlang/jq/commit/2f09060afab23fe9390cce7cb860b10416e1bf5f"},{"signature_version":"v1","source":"https://github.com/jqlang/jq/commit/2f09060afab23fe9390cce7cb860b10416e1bf5f","target":{"file":"src/jv_parse.c"},"deprecated":false,"digest":{"line_hashes":["159327352766948974014880466537272337191","206613873127793645204435291849754007209","187473737466624667232140801196719577201","168730623363307008103535459005129738467","220339632937479546282868978076064728579"],"threshold":0.9},"id":"CVE-2026-39979-be1b7201","signature_type":"Line"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39979.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"}]}