From e987df0d463d85fd70825e042a082427e8275b86 Mon Sep 17 00:00:00 2001 From: itchyny Date: Mon, 8 Jun 2026 22:14:48 +0900 Subject: [PATCH] Fix heap-buffer-overflow in raw file loading When `jv_string_append_buf` overflows the string length limit, it returns an invalid `jv`; `jv_load_file` then re-entered it on the invalid value and overran the heap. Break out of the loop once the value is invalid. Fixes CVE-2026-49839. CVE: CVE-2026-49839 Upstream: https://github.com/jqlang/jq/commit/e987df0d463d85fd70825e042a082427e8275b86 Signed-off-by: Thomas Perale --- src/jv_file.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/jv_file.c b/src/jv_file.c index 7706b0e06e..fbc1e4d653 100644 --- a/src/jv_file.c +++ b/src/jv_file.c @@ -57,6 +57,8 @@ jv jv_load_file(const char* filename, int raw) { if (raw) { data = jv_string_append_buf(data, buf, n); + if (!jv_is_valid(data)) + break; } else { jv_parser_set_buf(parser, buf, n, !feof(file)); jv value;