jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch for the issue.
History

Wed, 09 Jul 2025 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Eus
Redhat rhel Eus Long Life
Redhat rhel Tus
CPEs cpe:/a:redhat:enterprise_linux:8
cpe:/a:redhat:rhel_aus:8.2
cpe:/a:redhat:rhel_aus:8.4
cpe:/a:redhat:rhel_aus:8.6
cpe:/a:redhat:rhel_e4s:8.6
cpe:/a:redhat:rhel_e4s:8.8
cpe:/a:redhat:rhel_e4s:9.0
cpe:/a:redhat:rhel_e4s:9.2
cpe:/a:redhat:rhel_eus_long_life:8.6
cpe:/a:redhat:rhel_tus:8.6
cpe:/a:redhat:rhel_tus:8.8
cpe:/o:redhat:enterprise_linux:9
cpe:/o:redhat:rhel_eus:9.4
Vendors & Products Redhat
Redhat enterprise Linux
Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Eus
Redhat rhel Eus Long Life
Redhat rhel Tus

Fri, 20 Jun 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Jqlang
Jqlang jq
CPEs cpe:2.3:a:jqlang:jq:*:*:*:*:*:*:*:*
Vendors & Products Jqlang
Jqlang jq

Fri, 06 Jun 2025 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Thu, 22 May 2025 02:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 21 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 21 May 2025 14:45:00 +0000

Type Values Removed Values Added
Description jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch for the issue.
Title jq has signed integer overflow in jv.c:jvp_array_write
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-05-21T14:57:18.378Z

Reserved: 2024-01-15T15:19:19.443Z

Link: CVE-2024-23337

cve-icon Vulnrichment

Updated: 2025-05-21T14:57:10.804Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-21T15:16:03.920

Modified: 2025-06-20T17:41:15.807

Link: CVE-2024-23337

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-05-21T14:34:51Z

Links: CVE-2024-23337 - Bugzilla