[Git][security-tracker-team/security-tracker][master] DSA for jq
Aron Xu (@aron)
aron at debian.org
Fri Aug 7 02:49:31 BST 2026
Aron Xu pushed to branch master at Debian Security Tracker / security-tracker
Commits:
db8187a5 by Aron Xu at 2026-08-07T09:49:11+08:00
DSA for jq
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -68323,7 +68323,6 @@ CVE-2026-44991 (OpenClaw before 2026.4.21 contains an authorization bypass vulne
CVE-2026-44777 (jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordi ...)
{DLA-4662-1 DLA-4599-1}
- jq 1.8.1-6 (bug #1136445)
- [trixie] - jq <no-dsa> (Minor issue)
NOTE: https://github.com/jqlang/jq/security/advisories/GHSA-rmpv-jgvr-wpr9
CVE-2026-44738 (Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandb ...)
NOT-FOR-US: Grav CMS
@@ -68364,7 +68363,6 @@ CVE-2026-43968 (Improper Neutralization of CRLF Sequences ('CRLF Injection') vul
CVE-2026-43896 (jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded r ...)
{DLA-4662-1 DLA-4599-1}
- jq 1.8.1-6 (bug #1136445)
- [trixie] - jq <no-dsa> (Minor issue)
NOTE: https://github.com/jqlang/jq/security/advisories/GHSA-mg96-6h3q-g846
CVE-2026-43895 (jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts ...)
{DLA-4662-1 DLA-4599-1}
@@ -68448,12 +68446,10 @@ CVE-2026-41431 (Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser sh
CVE-2026-41257 (jq is a command-line JSON processor. In 1.8.1 and earlier, the jq byte ...)
{DLA-4662-1 DLA-4599-1}
- jq 1.8.1-6 (bug #1136445)
- [trixie] - jq <no-dsa> (Minor issue)
NOTE: https://github.com/jqlang/jq/security/advisories/GHSA-4jm8-m363-4539
CVE-2026-41256 (jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level j ...)
{DLA-4662-1 DLA-4599-1}
- jq 1.8.1-6 (bug #1136445)
- [trixie] - jq <no-dsa> (Minor issue)
NOTE: https://github.com/jqlang/jq/security/advisories/GHSA-vf2h-chrj-q3fg
CVE-2026-41250 (Taiga is a project management platform for startups and agile develope ...)
NOT-FOR-US: Taiga
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[07 Aug 2026] DSA-6416-1 jq - security update
+ {CVE-2024-53427 CVE-2026-32316 CVE-2026-40612 CVE-2026-41256 CVE-2026-41257 CVE-2026-43894 CVE-2026-43895 CVE-2026-43896 CVE-2026-44777 CVE-2026-47770 CVE-2026-49839 CVE-2026-54679}
+ [trixie] - jq 1.7.1-6+deb13u3
[06 Aug 2026] DSA-6415-1 linux - security update
{CVE-2025-40098 CVE-2026-45897 CVE-2026-45901 CVE-2026-53078 CVE-2026-53090 CVE-2026-64205 CVE-2026-64280 CVE-2026-64290 CVE-2026-64561 CVE-2026-64562 CVE-2026-64563 CVE-2026-64564 CVE-2026-64565 CVE-2026-64567 CVE-2026-64568 CVE-2026-64569 CVE-2026-64570 CVE-2026-64571 CVE-2026-64572 CVE-2026-64573 CVE-2026-64574 CVE-2026-64576 CVE-2026-64577 CVE-2026-64578 CVE-2026-64579 CVE-2026-64580 CVE-2026-64583 CVE-2026-64584}
[trixie] - linux 6.12.101-1
=====================================
data/dsa-needed.txt
=====================================
@@ -52,9 +52,6 @@ jetty9
--
jetty12
--
-jq (aron)
- possibly move trixie to 1.8.2
---
jupyterlab
--
kamailio
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/db8187a502c372475f26776732ce28ad84d760d2
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/db8187a502c372475f26776732ce28ad84d760d2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260807/367b1017/attachment.htm>
More information about the debian-security-tracker-commits
mailing list