Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 520
Alerts This Week
Warning Icon 1 520

SUSE Linux Enterprise Server jq Important Stack Issues Patch 2026-22637-1

suse
Calendar Grey July 16, 2026
Scroller Suse
SUSE update addresses important security issues in jq, including stack exhaustion and buffer overruns, ensuring system integrity.
SUSE has released an important security update for jq, addressing four vulnerabilities concerning recursion, oversized strings, and integer overflow, applicable to SUSE Linux Enter...

Summary

## This update for jq fixes the following issues * CVE-2026-43896: unbounded recursion in jv_object_merge_recursive() can lead to C stack exhaustion and a process crash (bsc#1265075). * CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076). * CVE-2026-49839: fixed a bug where jq --rawfile can turn a handled oversized- string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds (bsc#1269220). * CVE-2026-54679: integer overflow in jvp_string_append can lead to a buffer overrun on 32-bit systems (bsc#1269390). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

* bsc#1265075

* bsc#1265076

* bsc#1269220

* bsc#1269390

Cross-

* CVE-2026-43896

* CVE-2026-44777

* CVE-2026-49839

* CVE-2026-54679

CVSS scores:

* CVE-2026-43896 ( SUSE ): 6.8

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2026-43896 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2026-43896 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-43896 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-44777 ( SUSE ): 6.8

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2026-44777 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2026-44777 ( NVD ): 5.4

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22637-1
Release Date: 2026-07-13T10:47:46Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.