From 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b Mon Sep 17 00:00:00 2001 From: itchyny Date: Mon, 13 Apr 2026 08:46:11 +0900 Subject: [PATCH] Fix NUL truncation in the JSON parser This fixes CVE-2026-33948. Upstream: https://github.com/jqlang/jq/commit/6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b CVE: CVE-2026-33948 [thomas: remove tests] Signed-off-by: Thomas Perale --- src/util.c | 8 +------- tests/shtest | 6 ++++++ 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/src/util.c b/src/util.c index fdfdb96d88..80d65fc808 100644 --- a/src/util.c +++ b/src/util.c @@ -309,13 +309,7 @@ static int jq_util_input_read_more(jq_util_input_state *state) { if (p != NULL) state->current_line++; - if (p == NULL && state->parser != NULL) { - /* - * There should be no NULs in JSON texts (but JSON text - * sequences are another story). - */ - state->buf_valid_len = strlen(state->buf); - } else if (p == NULL && feof(state->current_input)) { + if (p == NULL && feof(state->current_input)) { size_t i; /*