SUSE-SU-2026:4275-1: important: Security update for jq

SLE-SECURITY-UPDATES null at suse.de
Mon Sep 21 12:31:10 UTC 2026


# Security update for jq

Announcement ID: SUSE-SU-2026:4275-1  
Release Date: 2026-09-21T07:33:04Z  
Rating: important  
References:

  * bsc#1215737
  * bsc#1218034
  * bsc#1218038
  * bsc#1238078
  * bsc#1248600
  * bsc#1262043
  * bsc#1262072
  * bsc#1265060
  * bsc#1265061
  * bsc#1265062
  * bsc#1265070
  * bsc#1265071
  * bsc#1265075
  * bsc#1265076
  * bsc#1269220
  * bsc#1269221
  * bsc#1269390
  * bsc#976992
  * jsc#PED-16516

  
Cross-References:

  * CVE-2015-8863
  * CVE-2023-50246
  * CVE-2023-50268
  * CVE-2024-53427
  * CVE-2025-9403
  * CVE-2026-33948
  * CVE-2026-40164
  * CVE-2026-40612
  * CVE-2026-41256
  * CVE-2026-41257
  * CVE-2026-43894
  * CVE-2026-43895
  * CVE-2026-43896
  * CVE-2026-44777
  * CVE-2026-47770
  * CVE-2026-49839
  * CVE-2026-54679

  
CVSS scores:

  * CVE-2015-8863 ( NVD ):  9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-50246 ( SUSE ):  6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-50246 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-50246 ( NVD ):  6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-50268 ( SUSE ):  6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-50268 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2024-53427 ( SUSE ):  5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
  * CVE-2024-53427 ( NVD ):  8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  * CVE-2025-9403 ( SUSE ):  1.9
    CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2025-9403 ( SUSE ):  3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
  * CVE-2025-9403 ( NVD ):  1.9
    CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2025-9403 ( NVD ):  3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
  * CVE-2025-9403 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-33948 ( SUSE ):  2.9
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-33948 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-33948 ( NVD ):  2.9
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-33948 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-40164 ( SUSE ):  6.8
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-40164 ( SUSE ):  5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2026-40164 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-40164 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-40612 ( SUSE ):  6.9
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-40612 ( SUSE ):  6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
  * CVE-2026-40612 ( NVD ):  5.4
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-40612 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2026-41256 ( SUSE ):  6.8
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-41256 ( SUSE ):  5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  * CVE-2026-41256 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  * CVE-2026-41257 ( SUSE ):  7.3
    CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-41257 ( SUSE ):  7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-41257 ( NVD ):  6.4
    CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-41257 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2026-43894 ( SUSE ):  8.5
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-43894 ( SUSE ):  7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-43894 ( NVD ):  6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-43894 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-43895 ( SUSE ):  4.8
    CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-43895 ( SUSE ):  4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-43895 ( NVD ):  4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-43896 ( SUSE ):  6.8
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-43896 ( SUSE ):  5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2026-43896 ( NVD ):  6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-43896 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-44777 ( SUSE ):  6.8
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-44777 ( SUSE ):  5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2026-44777 ( NVD ):  5.4
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-44777 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2026-47770 ( SUSE ):  5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2026-47770 ( NVD ):  6.8
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-47770 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2026-49839 ( SUSE ):  7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
  * CVE-2026-49839 ( NVD ):  7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
  * CVE-2026-54679 ( SUSE ):  9.2
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-54679 ( SUSE ):  8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-54679 ( NVD ):  6.9
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-54679 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

  
Affected Products:

  * Basesystem Module 15-SP7
  * SUSE Linux Enterprise Desktop 15 SP7
  * SUSE Linux Enterprise High Performance Computing 15 SP4
  * SUSE Linux Enterprise High Performance Computing 15 SP5
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
  * SUSE Linux Enterprise Micro 5.3
  * SUSE Linux Enterprise Micro 5.4
  * SUSE Linux Enterprise Micro 5.5
  * SUSE Linux Enterprise Micro for Rancher 5.3
  * SUSE Linux Enterprise Micro for Rancher 5.4
  * SUSE Linux Enterprise Real Time 15 SP7
  * SUSE Linux Enterprise Server 15 SP4
  * SUSE Linux Enterprise Server 15 SP4 LTSS
  * SUSE Linux Enterprise Server 15 SP5
  * SUSE Linux Enterprise Server 15 SP5 LTSS
  * SUSE Linux Enterprise Server 15 SP6
  * SUSE Linux Enterprise Server 15 SP6 LTSS
  * SUSE Linux Enterprise Server 15 SP7
  * SUSE Linux Enterprise Server for SAP Applications 15 SP4
  * SUSE Linux Enterprise Server for SAP Applications 15 SP5
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6
  * SUSE Linux Enterprise Server for SAP Applications 15 SP7

  
  
An update that solves 17 vulnerabilities, contains one feature and has one
security fix can now be installed.

## Description:

This update for jq fixes the following issues:

Security issues fixed:

  * CVE-2015-8863: heap buffer overflow in tokenadd() function (bsc#976992).
  * CVE-2023-50246: improper memory handling can lead to a heap buffer overflow
    in `decNumberToString` (bsc#1218034).
  * CVE-2023-50268: stack-based buffer overflow in builds using decNumber
    (bsc#1218038).
  * CVE-2024-53427: stack-buffer-overflow in the decNumberCopy function in
    decNumber.c (bsc#1238078).
  * CVE-2025-9403: reachable assertion in run_jq_tests() (bsc#1248600).
  * CVE-2026-33948: CLI input parsing allows validation bypass via embedded NUL
    bytes (bsc#1262043).
  * CVE-2026-40164: predictable hash collisions can lead to a denial of service
    (bsc#1262072).
  * CVE-2026-40612: jv_contains recurses into nested arrays/objects with no
    depth limit and can cause a stack overflow (bsc#1265060).
  * CVE-2026-41256: embedded NUL truncates top-level jq programs loaded with -f
    and can lead to execution of unintended programs (bsc#1265061).
  * CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory
    corruption and DoS (bsc#1265062).
  * CVE-2026-43894: signed integer overflow in `decNumber` can lead to out-of-
    bounds memory write (bsc#1265070).
  * CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass
    and sensitive information disclosure (bsc#1265071).
  * CVE-2026-43896: unbounded recursion in `jv_object_merge_recursive()` can
    lead to C stack exhaustion and a process crash (bsc#1265075).
  * CVE-2026-44777: uncontrolled recursion in ordinary module loader when two
    valid modules `include` each other can lead to stack exhaustion and process
    crash (bsc#1265076).
  * CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221).
  * CVE-2026-49839: `--rawfile` invalid-state reuse after `String too long` can
    lead to a heap buffer overflow (bsc#1269220).
  * CVE-2026-54679: integer overflow in `jvp_string_append` can lead to a buffer
    overrun on 32-bit systems (bsc#1269390).

Changes for jq:

Update to version 1.7.1:

  * Make the default background color more suitable for bright backgrounds.
  * Allow passing the inline jq script after --.
  * Fix possible uninitialised value dereference if jq_init() fails
  * Simplify paths/0 and paths/1.
  * Reject U+001F in string literals.
  * Remove unused nref accumulator in block_bind_library.
  * Remove a bunch of unused variables, and useless assignments.
  * main.c: Remove unused EXIT_STATUS_EXACT option.
  * Actually use the number correctly casted from double to int as index.
  * src/builtin.c: remove unnecessary jv_copy-s in type_error/type_error2.
  * Remove undefined behavior caught by LLVM 10 UBSAN.
  * Convert decnum to binary64 (double) instead of decimal64. This makes jq
    behave like the JSON specification suggests and more similar to other
    languages.
  * Fix memory leaks on invalid input for ltrimstr/1 and rtrimstr/1.
  * Fix memory leak on failed get for setpath/2.
  * Fix nan from json parsing also for nans with payload that start with 'n'.
  * Allow carriage return characters in comments.
  * Generate links in the man page.
  * Add extern C for C++.
  * Make object key color configurable using JQ_COLORS environment variable.
  * Change the default color of null to Bright Black.
  * Respect NO_COLOR environment variable to disable color output.
  * Improved --help output. Now mentions all options and nicer order.
  * Fix multiple issues of exit code using --exit-code/-e option.
  * Add --raw-output0 for NUL (zero byte) separated output.
  * Fix assert crash and validate JSON for --jsonarg.
  * Remove deprecated --argfile option.
  * Use decimal number literals to preserve precision. Comparison operations
    respects precision but arithmetic operations might truncate.
  * Adds new builtin pick(stream) to emit a projection of the input object or
    array.
  * Adds new builtin debug(msgs) that works like debug but applies a filter on
    the input before writing to stderr.
  * Adds new builtin scan($re; $flags). Was documented but not implemented.
  * Adds new builtin abs to get absolute value. This potentially allows the
    literal value of numbers to be preserved as length and fabs convert to
    float.
  * Allow if without else-branch. When skipped the else-branch will be .
    (identity).
  * Allow use of $binding as key in object literals.
  * Allow dot between chained indexes when using .["index"]
  * Allow dot for chained value iterator .[], .[]?
  * Fix try/catch catches more than it should.
  * Speed up and refactor some builtins, also remove scalars_or_empty/0.
  * Now halt and halt_error exit immediately instead of continuing to the next
    input.
  * Fix issue converting string to number after previous convert error.
  * Fix issue representing large numbers on some platforms causing invalid JSON
    output.
  * Fix deletion using assigning empty against arrays.
  * Allow keywords to be used as binding name in more places.
  * Allow using nan as NaN in JSON.
  * Expose a module's function names in modulemeta.
  * Fix contains/1 to handle strings with NUL.
  * Fix stderr/0 to output raw text without any decoration.
  * Fix nth/2 to emit empty on index out of range.
  * Fix implode to not assert and instead replace invalid unicode codepoints.
  * Fix indices/1 and rindex/1 in case of overlapping matches in strings.
  * Fix sub/3 to resolve issues involving global search-and-replace (gsub)
    operations.
  * Fix empty regular expression matches.
  * Fix overflow exception of the modulo operator.
  * Fix string multiplication by 0 (and less than 1) to emit empty string.
  * Fix segfault when using libjq and threads.
  * Fix constant folding of division and reminder with zero divisor.
  * Fix error/0, error/1 to throw null error.
  * Simpler and faster transpose.
  * Simple and efficient implementation of walk/1.
  * Remove deprecated filters leaf_paths, recurse_down.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server for SAP Applications 15 SP4  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4275

  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4275

  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4275

  * SUSE Linux Enterprise Micro for Rancher 5.3  
    zypper in -t patch SUSE-SLE-Micro-5.3-2026-4275

  * SUSE Linux Enterprise Micro 5.3  
    zypper in -t patch SUSE-SLE-Micro-5.3-2026-4275

  * SUSE Linux Enterprise Server for SAP Applications 15 SP5  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4275

  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4275

  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4275

  * SUSE Linux Enterprise Micro for Rancher 5.4  
    zypper in -t patch SUSE-SLE-Micro-5.4-2026-4275

  * SUSE Linux Enterprise Micro 5.4  
    zypper in -t patch SUSE-SLE-Micro-5.4-2026-4275

  * SUSE Linux Enterprise Server for SAP Applications 15 SP6  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4275

  * SUSE Linux Enterprise Micro 5.5  
    zypper in -t patch SUSE-SLE-Micro-5.5-2026-4275

  * SUSE Linux Enterprise Server 15 SP4 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4275

  * Basesystem Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4275

  * SUSE Linux Enterprise Server 15 SP5 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4275

  * SUSE Linux Enterprise Server 15 SP6 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4275

## Package List:

  * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
    * libjq-devel-1.7.1-150000.3.25.1
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
    x86_64)
    * libjq-devel-1.7.1-150000.3.25.1
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
    x86_64)
    * libjq-devel-1.7.1-150000.3.25.1
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1
  * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1
  * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
    * libjq-devel-1.7.1-150000.3.25.1
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
    x86_64)
    * libjq-devel-1.7.1-150000.3.25.1
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
    x86_64)
    * libjq-devel-1.7.1-150000.3.25.1
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1
  * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1
  * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
    * libjq-devel-1.7.1-150000.3.25.1
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1
  * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1
  * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
    * libjq-devel-1.7.1-150000.3.25.1
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1
  * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
    * libjq-devel-1.7.1-150000.3.25.1
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1
  * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
    * libjq-devel-1.7.1-150000.3.25.1
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1
  * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
    * libjq-devel-1.7.1-150000.3.25.1
    * jq-1.7.1-150000.3.25.1
    * libjq1-1.7.1-150000.3.25.1
    * jq-debuginfo-1.7.1-150000.3.25.1
    * libjq1-debuginfo-1.7.1-150000.3.25.1
    * jq-debugsource-1.7.1-150000.3.25.1

## References:

  * https://www.suse.com/security/cve/CVE-2015-8863.html
  * https://www.suse.com/security/cve/CVE-2023-50246.html
  * https://www.suse.com/security/cve/CVE-2023-50268.html
  * https://www.suse.com/security/cve/CVE-2024-53427.html
  * https://www.suse.com/security/cve/CVE-2025-9403.html
  * https://www.suse.com/security/cve/CVE-2026-33948.html
  * https://www.suse.com/security/cve/CVE-2026-40164.html
  * https://www.suse.com/security/cve/CVE-2026-40612.html
  * https://www.suse.com/security/cve/CVE-2026-41256.html
  * https://www.suse.com/security/cve/CVE-2026-41257.html
  * https://www.suse.com/security/cve/CVE-2026-43894.html
  * https://www.suse.com/security/cve/CVE-2026-43895.html
  * https://www.suse.com/security/cve/CVE-2026-43896.html
  * https://www.suse.com/security/cve/CVE-2026-44777.html
  * https://www.suse.com/security/cve/CVE-2026-47770.html
  * https://www.suse.com/security/cve/CVE-2026-49839.html
  * https://www.suse.com/security/cve/CVE-2026-54679.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1215737
  * https://bugzilla.suse.com/show_bug.cgi?id=1218034
  * https://bugzilla.suse.com/show_bug.cgi?id=1218038
  * https://bugzilla.suse.com/show_bug.cgi?id=1238078
  * https://bugzilla.suse.com/show_bug.cgi?id=1248600
  * https://bugzilla.suse.com/show_bug.cgi?id=1262043
  * https://bugzilla.suse.com/show_bug.cgi?id=1262072
  * https://bugzilla.suse.com/show_bug.cgi?id=1265060
  * https://bugzilla.suse.com/show_bug.cgi?id=1265061
  * https://bugzilla.suse.com/show_bug.cgi?id=1265062
  * https://bugzilla.suse.com/show_bug.cgi?id=1265070
  * https://bugzilla.suse.com/show_bug.cgi?id=1265071
  * https://bugzilla.suse.com/show_bug.cgi?id=1265075
  * https://bugzilla.suse.com/show_bug.cgi?id=1265076
  * https://bugzilla.suse.com/show_bug.cgi?id=1269220
  * https://bugzilla.suse.com/show_bug.cgi?id=1269221
  * https://bugzilla.suse.com/show_bug.cgi?id=1269390
  * https://bugzilla.suse.com/show_bug.cgi?id=976992
  * https://jira.suse.com/browse/PED-16516

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260921/9d157019/attachment.htm>


More information about the sle-security-updates mailing list