Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Ubuntu 20.04 LTS: jq Important Denial of Service Vulnerabilities USN-7657-2

Ubuntu Large Esm H500
Several security issues were fixed in jq.
==========================================================================
Ubuntu Security Notice USN-7657-2
July 22, 2025

jq vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in jq.

Software Description:
- jq: lightweight and flexible command-line JSON processor

Details:

USN-7657-1 fixed CVE-2024-23337 and CVE-2025-48060 in jq. This update
provides the corresponding fixes for Ubuntu 20.04 LTS, Ubuntu 18.04 LTS,
and Ubuntu 16.04 LTS.

Original advisory details:

It was discovered that jq incorrectly handled certain values when parsing
JSON data. A remote attacker could possibly use this issue to cause jq to
crash, resulting in a denial of service. (CVE-2024-23337)

It was discovered that jq incorrectly handled certain values when parsing
JSON data. A remote attacker could use this issue to cause jq to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2025-48060)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
  jq                              1.6-1ubuntu0.20.04.1+esm1
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  jq                              1.5+dfsg-2ubuntu0.1~esm1
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  jq                              1.5+dfsg-1ubuntu0.1+esm3
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-7657-2
  https://ubuntu.com/security/notices/USN-7657-2
  CVE-2024-23337, CVE-2025-48060

Ubuntu 20.04 LTS: jq Important Denial of Service Vulnerabilities USN-7657-2

ubuntu
Calendar Grey July 23, 2025
Dist Ubuntu Esm H88
Urgent jq security patch launched for Ubuntu rectifies multiple critical vulnerabilities that could lead to possible DoS threats.
Several security issues were fixed in jq.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in jq. Software Description: - jq: lightweight and flexible command-line JSON processor Details: USN-7657-1 fixed CVE-2024-23337 and CVE-2025-48060 in jq. This update provides the corresponding fixes for Ubuntu 20.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 16.04 LTS. Original advisory details: It was discovered that jq incorrectly handled certain values when parsing JSON data. A remote attacker could possibly use this issue to cause jq to crash, resulting in a denial of service. (CVE-2024-23337) It was discovered that jq incorrectly handled certain values when parsing JSON data. A remote attacker could use this issue to cause jq to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2025-48060)

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS jq 1.6-1ubuntu0.20.04.1+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS jq 1.5+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS jq 1.5+dfsg-1ubuntu0.1+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7657-2

https://ubuntu.com/security/notices/USN-7657-2

CVE-2024-23337, CVE-2025-48060

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7657-2

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here