CVE-2025-9403

Vulnerability

CVE-2025-9403

jq: assertion failure in run_jq_tests() of the file jq_test.c

ecosystem: redhat:8, redhat:9, redhat:10

A vulnerability has been identified in the jq JSON processor where malformed JSON input containing invalid Unicode escape sequences can trigger an assertion failure in the test suite’s parsing consistency checks. This flaw arises from inconsistencies between expected and reparsed JSON values during serialization and deserialization, potentially allowing an attacker to exploit the issue by supplying specially crafted JSON data to cause abnormal termination or denial of service during test execution, highlighting weaknesses in jq’s parsing reliability.

References
severityL
Low

type: vendor

source: secalert@redhat.com

CVSS3.1
3.3LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

AVLocal
ACLow
PRNone
UIRequired
SNot Changed
CNone
INone
ALow

source: secalert@redhat.com

 CWE
CWE-617

Reachable Assertion

source: secalert@redhat.com

published: 2025-08-25 02:02:07

modified: 2025-08-26 07:30:29

Detection

redhat:10

OR

unfixedFix deferred

 

jq

package type: source

type: version

tag: rhel-10:431d6dc1-c8b2-f412-2d39-f649104b14bc

redhat:8

OR

unfixedFix deferred

 

jq

package type: source

type: version

tag: rhel-8-including-unpatched:71a3c4c9-47a5-8bbf-0ab5-6a6ecfc3a961

redhat:9

OR

unfixedFix deferred

 

jq

package type: source

type: version

tag: rhel-9-including-unpatched:71a3c971-eaa5-8bbf-0ab5-6a6ed1b3239e

Data Sources

  • RedHat Enterprise Linux CSAF VEX

    redhat-vex

VulsFutureVuls|GitHub