SUSE-SU-2026:4275-1: important: Security update for jq
SLE-SECURITY-UPDATES
null at suse.de
Mon Sep 21 12:31:10 UTC 2026
# Security update for jq
Announcement ID: SUSE-SU-2026:4275-1
Release Date: 2026-09-21T07:33:04Z
Rating: important
References:
* bsc#1215737
* bsc#1218034
* bsc#1218038
* bsc#1238078
* bsc#1248600
* bsc#1262043
* bsc#1262072
* bsc#1265060
* bsc#1265061
* bsc#1265062
* bsc#1265070
* bsc#1265071
* bsc#1265075
* bsc#1265076
* bsc#1269220
* bsc#1269221
* bsc#1269390
* bsc#976992
* jsc#PED-16516
Cross-References:
* CVE-2015-8863
* CVE-2023-50246
* CVE-2023-50268
* CVE-2024-53427
* CVE-2025-9403
* CVE-2026-33948
* CVE-2026-40164
* CVE-2026-40612
* CVE-2026-41256
* CVE-2026-41257
* CVE-2026-43894
* CVE-2026-43895
* CVE-2026-43896
* CVE-2026-44777
* CVE-2026-47770
* CVE-2026-49839
* CVE-2026-54679
CVSS scores:
* CVE-2015-8863 ( NVD ): 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2023-50246 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2023-50246 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2023-50246 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2023-50268 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2023-50268 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2024-53427 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
* CVE-2024-53427 ( NVD ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2025-9403 ( SUSE ): 1.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2025-9403 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-9403 ( NVD ): 1.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2025-9403 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-9403 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-33948 ( SUSE ): 2.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-33948 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-33948 ( NVD ): 2.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-33948 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-40164 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-40164 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-40612 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-40612 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
* CVE-2026-40612 ( NVD ): 5.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-40612 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-41256 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-41256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-41256 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-41257 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41257 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-41257 ( NVD ): 6.4
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41257 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43894 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-43894 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43894 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43894 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43895 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-43895 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-43895 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-43896 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-43896 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43896 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43896 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-44777 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-44777 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-44777 ( NVD ): 5.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-44777 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-47770 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-47770 ( NVD ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-47770 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-49839 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
* CVE-2026-49839 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
* CVE-2026-54679 ( SUSE ): 9.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-54679 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-54679 ( NVD ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-54679 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products:
* Basesystem Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves 17 vulnerabilities, contains one feature and has one
security fix can now be installed.
## Description:
This update for jq fixes the following issues:
Security issues fixed:
* CVE-2015-8863: heap buffer overflow in tokenadd() function (bsc#976992).
* CVE-2023-50246: improper memory handling can lead to a heap buffer overflow
in `decNumberToString` (bsc#1218034).
* CVE-2023-50268: stack-based buffer overflow in builds using decNumber
(bsc#1218038).
* CVE-2024-53427: stack-buffer-overflow in the decNumberCopy function in
decNumber.c (bsc#1238078).
* CVE-2025-9403: reachable assertion in run_jq_tests() (bsc#1248600).
* CVE-2026-33948: CLI input parsing allows validation bypass via embedded NUL
bytes (bsc#1262043).
* CVE-2026-40164: predictable hash collisions can lead to a denial of service
(bsc#1262072).
* CVE-2026-40612: jv_contains recurses into nested arrays/objects with no
depth limit and can cause a stack overflow (bsc#1265060).
* CVE-2026-41256: embedded NUL truncates top-level jq programs loaded with -f
and can lead to execution of unintended programs (bsc#1265061).
* CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory
corruption and DoS (bsc#1265062).
* CVE-2026-43894: signed integer overflow in `decNumber` can lead to out-of-
bounds memory write (bsc#1265070).
* CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass
and sensitive information disclosure (bsc#1265071).
* CVE-2026-43896: unbounded recursion in `jv_object_merge_recursive()` can
lead to C stack exhaustion and a process crash (bsc#1265075).
* CVE-2026-44777: uncontrolled recursion in ordinary module loader when two
valid modules `include` each other can lead to stack exhaustion and process
crash (bsc#1265076).
* CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221).
* CVE-2026-49839: `--rawfile` invalid-state reuse after `String too long` can
lead to a heap buffer overflow (bsc#1269220).
* CVE-2026-54679: integer overflow in `jvp_string_append` can lead to a buffer
overrun on 32-bit systems (bsc#1269390).
Changes for jq:
Update to version 1.7.1:
* Make the default background color more suitable for bright backgrounds.
* Allow passing the inline jq script after --.
* Fix possible uninitialised value dereference if jq_init() fails
* Simplify paths/0 and paths/1.
* Reject U+001F in string literals.
* Remove unused nref accumulator in block_bind_library.
* Remove a bunch of unused variables, and useless assignments.
* main.c: Remove unused EXIT_STATUS_EXACT option.
* Actually use the number correctly casted from double to int as index.
* src/builtin.c: remove unnecessary jv_copy-s in type_error/type_error2.
* Remove undefined behavior caught by LLVM 10 UBSAN.
* Convert decnum to binary64 (double) instead of decimal64. This makes jq
behave like the JSON specification suggests and more similar to other
languages.
* Fix memory leaks on invalid input for ltrimstr/1 and rtrimstr/1.
* Fix memory leak on failed get for setpath/2.
* Fix nan from json parsing also for nans with payload that start with 'n'.
* Allow carriage return characters in comments.
* Generate links in the man page.
* Add extern C for C++.
* Make object key color configurable using JQ_COLORS environment variable.
* Change the default color of null to Bright Black.
* Respect NO_COLOR environment variable to disable color output.
* Improved --help output. Now mentions all options and nicer order.
* Fix multiple issues of exit code using --exit-code/-e option.
* Add --raw-output0 for NUL (zero byte) separated output.
* Fix assert crash and validate JSON for --jsonarg.
* Remove deprecated --argfile option.
* Use decimal number literals to preserve precision. Comparison operations
respects precision but arithmetic operations might truncate.
* Adds new builtin pick(stream) to emit a projection of the input object or
array.
* Adds new builtin debug(msgs) that works like debug but applies a filter on
the input before writing to stderr.
* Adds new builtin scan($re; $flags). Was documented but not implemented.
* Adds new builtin abs to get absolute value. This potentially allows the
literal value of numbers to be preserved as length and fabs convert to
float.
* Allow if without else-branch. When skipped the else-branch will be .
(identity).
* Allow use of $binding as key in object literals.
* Allow dot between chained indexes when using .["index"]
* Allow dot for chained value iterator .[], .[]?
* Fix try/catch catches more than it should.
* Speed up and refactor some builtins, also remove scalars_or_empty/0.
* Now halt and halt_error exit immediately instead of continuing to the next
input.
* Fix issue converting string to number after previous convert error.
* Fix issue representing large numbers on some platforms causing invalid JSON
output.
* Fix deletion using assigning empty against arrays.
* Allow keywords to be used as binding name in more places.
* Allow using nan as NaN in JSON.
* Expose a module's function names in modulemeta.
* Fix contains/1 to handle strings with NUL.
* Fix stderr/0 to output raw text without any decoration.
* Fix nth/2 to emit empty on index out of range.
* Fix implode to not assert and instead replace invalid unicode codepoints.
* Fix indices/1 and rindex/1 in case of overlapping matches in strings.
* Fix sub/3 to resolve issues involving global search-and-replace (gsub)
operations.
* Fix empty regular expression matches.
* Fix overflow exception of the modulo operator.
* Fix string multiplication by 0 (and less than 1) to emit empty string.
* Fix segfault when using libjq and threads.
* Fix constant folding of division and reminder with zero divisor.
* Fix error/0, error/1 to throw null error.
* Simpler and faster transpose.
* Simple and efficient implementation of walk/1.
* Remove deprecated filters leaf_paths, recurse_down.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4275
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4275
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4275
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-4275
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-4275
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4275
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4275
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4275
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-4275
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-4275
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4275
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-4275
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4275
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4275
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4275
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4275
## Package List:
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* libjq-devel-1.7.1-150000.3.25.1
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* libjq-devel-1.7.1-150000.3.25.1
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* libjq-devel-1.7.1-150000.3.25.1
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* libjq-devel-1.7.1-150000.3.25.1
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* libjq-devel-1.7.1-150000.3.25.1
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* libjq-devel-1.7.1-150000.3.25.1
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libjq-devel-1.7.1-150000.3.25.1
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* libjq-devel-1.7.1-150000.3.25.1
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libjq-devel-1.7.1-150000.3.25.1
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* libjq-devel-1.7.1-150000.3.25.1
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* libjq-devel-1.7.1-150000.3.25.1
* jq-1.7.1-150000.3.25.1
* libjq1-1.7.1-150000.3.25.1
* jq-debuginfo-1.7.1-150000.3.25.1
* libjq1-debuginfo-1.7.1-150000.3.25.1
* jq-debugsource-1.7.1-150000.3.25.1
## References:
* https://www.suse.com/security/cve/CVE-2015-8863.html
* https://www.suse.com/security/cve/CVE-2023-50246.html
* https://www.suse.com/security/cve/CVE-2023-50268.html
* https://www.suse.com/security/cve/CVE-2024-53427.html
* https://www.suse.com/security/cve/CVE-2025-9403.html
* https://www.suse.com/security/cve/CVE-2026-33948.html
* https://www.suse.com/security/cve/CVE-2026-40164.html
* https://www.suse.com/security/cve/CVE-2026-40612.html
* https://www.suse.com/security/cve/CVE-2026-41256.html
* https://www.suse.com/security/cve/CVE-2026-41257.html
* https://www.suse.com/security/cve/CVE-2026-43894.html
* https://www.suse.com/security/cve/CVE-2026-43895.html
* https://www.suse.com/security/cve/CVE-2026-43896.html
* https://www.suse.com/security/cve/CVE-2026-44777.html
* https://www.suse.com/security/cve/CVE-2026-47770.html
* https://www.suse.com/security/cve/CVE-2026-49839.html
* https://www.suse.com/security/cve/CVE-2026-54679.html
* https://bugzilla.suse.com/show_bug.cgi?id=1215737
* https://bugzilla.suse.com/show_bug.cgi?id=1218034
* https://bugzilla.suse.com/show_bug.cgi?id=1218038
* https://bugzilla.suse.com/show_bug.cgi?id=1238078
* https://bugzilla.suse.com/show_bug.cgi?id=1248600
* https://bugzilla.suse.com/show_bug.cgi?id=1262043
* https://bugzilla.suse.com/show_bug.cgi?id=1262072
* https://bugzilla.suse.com/show_bug.cgi?id=1265060
* https://bugzilla.suse.com/show_bug.cgi?id=1265061
* https://bugzilla.suse.com/show_bug.cgi?id=1265062
* https://bugzilla.suse.com/show_bug.cgi?id=1265070
* https://bugzilla.suse.com/show_bug.cgi?id=1265071
* https://bugzilla.suse.com/show_bug.cgi?id=1265075
* https://bugzilla.suse.com/show_bug.cgi?id=1265076
* https://bugzilla.suse.com/show_bug.cgi?id=1269220
* https://bugzilla.suse.com/show_bug.cgi?id=1269221
* https://bugzilla.suse.com/show_bug.cgi?id=1269390
* https://bugzilla.suse.com/show_bug.cgi?id=976992
* https://jira.suse.com/browse/PED-16516
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260921/9d157019/attachment.htm>
More information about the sle-security-updates
mailing list