{"id":"CLSA-2026-1777322146","summary":"jq: Fix of CVE-2026-32316","details":"- CVE-2026-32316: fix heap buffer overflow in jvp_string_append and\n  jvp_string_copy_replace_bad caused by uint32_t overflow in size\n  calculations for strings exceeding INT_MAX bytes","modified":"2026-05-27T11:17:13.022631198Z","published":"2026-04-27T20:35:51Z","upstream":["CVE-2026-32316"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/almalinux9.2esu/CLSA-2026-1777322146.html"}],"affected":[{"package":{"name":"jq","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/jq?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6-14.el9.tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1777322146.json"}},{"package":{"name":"jq-devel","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/jq-devel?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6-14.el9.tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1777322146.json"}}],"schema_version":"1.7.5"}