Red Hat released Important security updates for jq across multiple RHEL 8, 9, and 10 channels, including standard, Extended Update Support, SAP, AUS, Telecommunications, and CodeReady Linux Builder repositories, to remediate CVE-2026-39979 and CVE-2026-40164. The first flaw, CVE-2026-39979, affects libjq and can trigger an out-of-bounds read in jv_parse_sized() when malformed JSON is parsed from a non-NUL-terminated buffer; the error path formats input with %s, which can read past the supplied buffer and potentially disclose memory or crash the process.
The second issue, CVE-2026-40164, allows CPU exhaustion through crafted JSON objects that force hash collisions because jq used MurmurHash3 with a hardcoded public seed, degrading hash-table operations to O(n²). Red Hat shipped patched packages including jq-1.6-19.el9_7.0.2 for RHEL 9, jq-1.7.1-11.el10_1.0.2 for RHEL 10, jq-1.7.1-8.el10_0.3 for RHEL 10.0 EUS, and additional fixed builds for RHEL 9.6, 9.4, 9.2, 9.0, and RHEL 8.6 service channels; upstream fixes were tied to commits 2f09060afab23fe9390cce7cb860b10416e1bf5f and 0c7d133c3c7e37c00b6d46b658a02244fdd3c784.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-19, Red Hat published RHSA-2026:19365, releasing jq 1.6-19.el9_8.2 updates for Red Hat Enterprise Linux 9 and related 9.8 channels, including Extended Update Support, Extended Life Cycle, SAP Update Services, 4-years-of-updates variants, and CodeReady Linux Builder. The Important-rated advisory fixes CVE-2026-39979 and CVE-2026-40164 across x86_64, aarch64, ppc64le, and s390x architectures.
On 2026-05-19, Red Hat published RHSA-2026:19151, releasing jq-1.7.1-11.el10_2.2 updates for Red Hat Enterprise Linux 10 and related 10.2 channels, including Extended Update Support, Extended Life Cycle, and CodeReady Linux Builder variants. The Important-rated advisory fixes CVE-2026-39979 and CVE-2026-40164 across multiple architectures.
On 2026-05-19, Red Hat published Bugzilla entry 2458084 for CVE-2026-40164, a jq denial-of-service issue caused by attacker-crafted JSON object key collisions against a hardcoded MurmurHash3 seed. The entry says the issue was fixed upstream in commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784 and later remediated in multiple RHEL and OpenShift advisories.
On 2026-05-19, Red Hat published Bugzilla entry 2458077 describing CVE-2026-39979, an out-of-bounds read in libjq's jv_parse_sized() error-handling path when malformed JSON is parsed from a non-NUL-terminated buffer. The entry notes the flaw was patched upstream in commit 2f09060afab23fe9390cce7cb860b10416e1bf5f and that Red Hat had issued fixes across multiple RHEL and OpenShift releases.
On 2026-05-18, Red Hat issued RHSA-2026:18040, RHSA-2026:18042, RHSA-2026:18043, RHSA-2026:18044, RHSA-2026:18045, and RHSA-2026:18047 to deliver jq updates for RHEL 10.0 EUS, RHEL 9.6 EUS, RHEL 9.4 channels, RHEL 9.2 SAP-related offerings, RHEL 9.0 SAP-related offerings, and RHEL 8.6 service channels. These advisories all fix CVE-2026-39979 and CVE-2026-40164 across additional supported architectures and repositories.
On 2026-05-13, Red Hat published RHSA-2026:16693 for RHEL 9 and RHSA-2026:16692 for RHEL 10, releasing updated jq packages that fix CVE-2026-39979 and CVE-2026-40164. Both advisories rate the update as Important and provide patched builds for multiple architectures and product variants.
On 2026-05-12, Red Hat published RHSA-2026:16252 for Red Hat Enterprise Linux 8, releasing updated jq 1.6-12.el8_10 packages that fix CVE-2026-39979 and CVE-2026-40164. The Important-rated advisory covers multiple RHEL 8, CodeReady Linux Builder, and Extended Life Cycle 8.10 variants across several architectures.
Red Hat published its CVE record for CVE-2026-39979, describing an Important-severity out-of-bounds read in jq's libjq jv_parse_sized() when malformed JSON is parsed from a non-NUL-terminated buffer. The entry included mitigation guidance to ensure buffers are NUL-terminated and linked the issue to Bugzilla 2458077 and the upstream fix.
Red Hat later released advisories for OpenShift Container Platform versions 4.12 through 4.19 to address the jq vulnerabilities, with advisories issued between June and July 2026. The Bugzilla records explicitly state that OpenShift fixes for CVE-2026-39979 and CVE-2026-40164 were delivered during that period.
On 2026-05-18, Red Hat published RHSA-2026:18048 to deliver jq fixes for RHEL 8.4 Advanced Mission Critical Update Support and RHEL 8.4 Extended Update Support Long-Life Add-On. The advisory addressed CVE-2026-40164 in additional RHEL 8.4 support streams not previously captured in the timeline.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
16 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.