CVE-2025-48060: AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt)
Published May 21, 2025
·Updated
AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt)
Affected Software
5 affected componentsFixes available
JQ jq<=1.7.1
jqlang jq<=1.7.1
Microsoft cbl2 jq 1.6-4
Microsoft cm2 jq 1.6-4
Microsoft azl3 jq 1.7.1-4
Event History
May 21, 2025
CVE Published
via MITRE·05:32 PM
Data Sourced
via MITRE·05:32 PM
DescriptionWeakness
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Jul 29, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Jan 30, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48060?
The severity of CVE-2025-48060 is considered to be critical due to the potential for heap-buffer-overflow vulnerabilities.
2
How do I fix CVE-2025-48060?
To fix CVE-2025-48060, users should upgrade jq to version 1.7.2 or later.
3
What versions of jq are affected by CVE-2025-48060?
CVE-2025-48060 affects jq versions up to and including 1.7.1.
4
What issues can arise from CVE-2025-48060?
CVE-2025-48060 can lead to application crashes and potential arbitrary code execution.
5
Is there a workaround for CVE-2025-48060?
There are no recommended workarounds for CVE-2025-48060; the best course of action is to update jq to a secure version.