Bug 2367807 (CVE-2024-23337) - CVE-2024-23337 jq: jq has signed integer overflow in jv.c:jvp_array_write
Summary: CVE-2024-23337 jq: jq has signed integer overflow in jv.c:jvp_array_write
Keywords:
Status: NEW
Alias: CVE-2024-23337
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2370297 2370298
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-05-21 15:01 UTC by OSIDB Bzimport
Modified: 2025-06-17 08:28 UTC (History)
32 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-05-21 15:01:17 UTC
jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch for the issue.


Note You need to log in before you can comment on or make changes to this bug.