CVE-2024-53427

CVE Information
CVE ID
CVE-2024-53427
Severity
HIGH CVSS 8.1
Publish Date
2025-02-26
Description

decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant stack-based buffer overflow and out-of-bounds write, as demonstrated by use of --slurp with subtraction, such as a filter of .-. when the input has a certain form of digit string with NaN (e.g., "1 NaN123" immediately followed by many more digits).

Collection Date
2026-01-13
Impact Summary
Affected Hosts 2
Related Incidents 0
Related Alerts 0
Affected Hosts (2)
Hostname OS Type Severity Total CVEs
inbridge-42 LINUX CRITICAL 142
inbridge-ubt-24 LINUX CRITICAL 2364