Skip to content

fix(jq): pin-forward to f43 for 5 CVEs#17269

Draft
tobiasb-ms wants to merge 1 commit into
tomls/base/mainfrom
tobiasb-ms/cve-fix-jq
Draft

fix(jq): pin-forward to f43 for 5 CVEs#17269
tobiasb-ms wants to merge 1 commit into
tomls/base/mainfrom
tobiasb-ms/cve-fix-jq

Conversation

@tobiasb-ms
Copy link
Copy Markdown
Contributor

CVE Pin-Forward: jq

Pins jq to Fedora f43 HEAD (7013b20) to pick up
5 CVE patches added upstream.

CVEs Resolved

CVE Severity Status
CVE-2026-32316 High Tracked
CVE-2026-40164 High Tracked
CVE-2026-33947 Additional
CVE-2026-39956 Additional
CVE-2026-39979 Additional

Fedora Spec Delta

Old commit: 1597363
New commit: 7013b20

New patches:

  • CVE-2026-32316.patch
  • CVE-2026-33947.patch
  • CVE-2026-39956.patch
  • CVE-2026-39979.patch
  • CVE-2026-40164.patch
  • skipped_too_deep.patch

Pin locks/jq.lock to Fedora f43 HEAD to pick up
CVE-specific patches added upstream.

CVEs resolved (2 tracked, 3 additional):

  Tracked:
    CVE-2026-32316 (High)
    CVE-2026-40164 (High)

  Additional:
    CVE-2026-33947
    CVE-2026-39956
    CVE-2026-39979

Fedora f43 spec delta (1597363..7013b20):
  + CVE-2026-32316.patch
  + CVE-2026-33947.patch
  + CVE-2026-39956.patch
  + CVE-2026-39979.patch
  + CVE-2026-40164.patch
  + skipped_too_deep.patch
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant