Multiple Vulnerabilities in jq Component (CVE-2026-39979, CVE-2026-40164)
39092
02 October 2026
02 October 2026
CLOSED
LOW
CVE-2026-39979, CVE-2026-40164
|
Brocade Security Advisory ID |
BSA-2026-4104 |
|
Component |
|
|
|
|
Summary
Brocade has released a security advisory addressing two Denial of Service (DoS) vulnerabilities in the third-party jq JSON processing component integrated into affected software releases. These vulnerabilities stem from improper memory bounds checking and inefficient algorithmic complexity, which could allow remote attackers to cause system instability or service crashes by submitting crafted JSON inputs.
Vulnerability Details
CVE-2026-39979: Denial of Service via Out-of-Bounds Read in jv_parse.c
- Severity / CVSS v3 Base Score: High / 7.4
- Common Weakness Enumeration: CWE-125 (Out-of-bounds Read)
- Description: An out-of-bounds read flaw exists in the JSON parser module (jv_parse.c) of jq. A remote, unauthenticated attacker could exploit this by feeding a specially crafted JSON payload to an application utilizing jq, causing the process to read beyond allocated memory boundaries, leading to application crashes or Denial of Service (DoS).
CVE-2026-40164: Denial of Service via Inefficient Algorithmic Complexity in jv.c
- Severity / CVSS v3 Base Score: Medium / 6.7
- Common Weakness Enumeration: CWE-400 (Uncontrolled Resource Consumption)
- Description: A flaw in the data structure management component (jv.c) of jq suffers from inefficient algorithmic time complexity. An attacker could exploit this vulnerability by submitting payloads that trigger worst-case resource utilization, resulting in excessive CPU consumption, responsiveness degradation, or service lockup.
Products Confirmed Not Affected
- Brocade ASCG: Vulnerable_code_not_in_execute_path
Solution
Although Brocade ASCG is not affected, a security update is provided in Brocade ASCG 3.5.0 OVA
Revision History
|
Version |
Change |
Date |
|
1.0 |
Initial Publication |
9/30/2026 |
Disclaimer
THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.