ELSA-2026-16693

ELSA-2026-16693 - jq security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-05-13

Description


[1.6-19.0.2]
- Fix CVE-2026-40164 - Denial of Service via crafted JSON object causing hash collisions
- Resolves: RHEL-168184

[1.6-19.1]
- Fix CVE-2026-39979 out-of-bounds read in jv_parse_sized()
- Resolves: RHEL-168201

[1.6-19]
- Fix CVE-2025-48060
- Resolves: RHEL-92993

[1.6-18]
- Fix CVE-2024-23337
- Resolves: RHEL-92975


Related CVEs


CVE-2026-39979
CVE-2026-40164

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) jq-1.6-19.el9_7.0.2.src.rpmb873e03d0510a4b6008213a7fef650a340b0e8e7b47840754c96561e3932b4de-ol9_aarch64_appstream
jq-1.6-19.el9_7.0.2.src.rpmb873e03d0510a4b6008213a7fef650a340b0e8e7b47840754c96561e3932b4de-ol9_aarch64_codeready_builder
jq-1.6-19.el9_7.0.2.aarch64.rpm64b6e6510ff9a279b4c749af1b65d39b4e871f4a939e76817fdb4fe51653ac06-ol9_aarch64_appstream
jq-devel-1.6-19.el9_7.0.2.aarch64.rpm0ba0eeb025eb999013b41ac7c551cbffd5bfdca3fed58f87790d1e40706d3c1d-ol9_aarch64_codeready_builder
Oracle Linux 9 (x86_64) jq-1.6-19.el9_7.0.2.src.rpmb873e03d0510a4b6008213a7fef650a340b0e8e7b47840754c96561e3932b4de-ol9_x86_64_appstream
jq-1.6-19.el9_7.0.2.src.rpmb873e03d0510a4b6008213a7fef650a340b0e8e7b47840754c96561e3932b4de-ol9_x86_64_codeready_builder
jq-1.6-19.el9_7.0.2.i686.rpmb68eaffcbd6fe4ad56afe95134cc77a9a4947761582d1fcd999f9045bcda05d6-ol9_x86_64_appstream
jq-1.6-19.el9_7.0.2.x86_64.rpmb161733cd788ef351e5739355a9f9d6288f8774476dc7aa84392cf1582d7b23d-ol9_x86_64_appstream
jq-devel-1.6-19.el9_7.0.2.i686.rpm3499c840fb598206dfccd7c75b6fa4d81d5a87833629dc87b2df12d843df92e4-ol9_x86_64_codeready_builder
jq-devel-1.6-19.el9_7.0.2.x86_64.rpm28bdd80333156c126c4aeaace4ef4d563990eda73edf3c8356c694ae88485d39-ol9_x86_64_codeready_builder



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete