Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (10)
📋 Description
CVE-2026-40612 — jq: stack overflow via unbounded recursion in jv_contains CVE-2026-41256 — jq: embedded NUL truncates top-level jq programs loaded with -f CVE-2026-41257 — jq: signed-int overflow in stack_reallocate CVE-2026-43894 — jq: jq: Arbitrary Code Execution or Denial of Service via Signed Integer Overflow CVE-2026-43895 — jq: embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts CVE-2026-43896 — jq: stack overflow in recursive object merge CVE-2026-44777 — jq: stack overflow in module loading on mutual include CVE-2026-47770 — jq: jq: Denial of Service via deeply nested array comparison CVE-2026-49839 — jq: jq: Heap out-of-bounds write via oversized raw file processing CVE-2026-54679 — jq: jq: Denial of Service via integer overflow and buffer overrun on 32-bit systems
🎯 Affected products4
- Red Hat Hardened Images
- jq-main@aarch64 as a component of Red Hat Hardened Images
- jq-main@src as a component of Red Hat Hardened Images
- jq-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Do not process untrusted input with the jq command line JSON processor. Workaround: Do not process untrusted filter files using the -f flag with the jq command line JSON processor. Workaround: Do not process untrusted scripts with the jq command line JSON processor. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Avoid using `jq --rawfile` with untrusted or user-controlled files.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2026:29986
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-43895
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-41256
- externalhttps://access.redhat.com/security/cve/CVE-2026-41257
- externalhttps://access.redhat.com/security/cve/CVE-2026-43896
- externalhttps://access.redhat.com/security/cve/CVE-2026-40612
- externalhttps://access.redhat.com/security/cve/CVE-2026-47770
- externalhttps://access.redhat.com/security/cve/CVE-2026-54679
- externalhttps://access.redhat.com/security/cve/CVE-2026-43894
- externalhttps://access.redhat.com/security/cve/CVE-2026-49839
- externalhttps://access.redhat.com/security/cve/CVE-2026-44777
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_29986.json