Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Ubuntu 26.04 LTS jq Important DoS and Code Exec Issues USN-8202-2

ubuntu
Calendar Grey April 28, 2026
Dist Ubuntu Esm H88
Critical updates for jq in Ubuntu 26.04 LTS address multiple critical issues including remote code execution risks.
Several security issues were fixed in jq.

Summary

Several security issues were fixed in jq.

Software Description:

Details:

USN-8202-1 fixed vulnerabilities in jq. This update provides the

corresponding update to Ubuntu 26.04 LTS.

Original advisory details:

It was discovered that jq did not correctly handle certain string

concatenations. An attacker could possibly use this issue to cause a

denial of service or execute arbitrary code. (CVE-2026-32316)

It was discovered that jq did not correctly handle recursion in certain

circumstances. An attacker could possibly use this issue to cause a denial

of service. (CVE-2026-33947)

It was discovered that jq did not correctly handle improperly terminated

strings. An attacker could possibly use this issue to cause a denial of

service or execute arbitrary code. (CVE-2026-33948)

It was discovered that jq did not correctly handle checking certain

variable types. An attacker could possibly use this issue to cause a

denial of service or leak sensitive information. (CVE-2026-3...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8202-2

https://ubuntu.com/security/notices/USN-8202-1

CVE-2026-32316, CVE-2026-33947, CVE-2026-33948, CVE-2026-39956,

CVE-2026-39979, CVE-2026-40164

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8202-2

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here