jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed
jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON object hash table operations, which allowed an attacker to precompute key collisions offline. By supplying a crafted JSON object (~100 KB) where all keys hashed to the same bucket, hash table lookups degraded from O(1) to O(n), turning any jq expression into an O(n²) operation and causing significant CPU exhaustion. This affected common jq use cases such as CI/CD pipelines, web services, and data processing scripts, and was far more practical to exploit than existing heap overflow issues since it required only a small payload. This issue has been patched in commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
HerstellerRed Hat
≫
ProduktRed Hat Enterprise Linux 10
Default Statusaffected
Version0:1.7.1-11.el10_1.0.2
Version <*
Statusunaffected
Version0:1.7.1-11.el10_2.2
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat Enterprise Linux 10.0 Extended Update Support
Default Statusaffected
Version0:1.7.1-8.el10_0.3
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat Enterprise Linux 8
Default Statusaffected
Version0:1.6-12.el8_10
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Default Statusaffected
Version0:1.5-12.el8_4.5
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Default Statusaffected
Version0:1.5-12.el8_4.5
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Default Statusaffected
Version0:1.6-3.el8_6.2
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat Enterprise Linux 8.6 Telecommunications Update Service
Default Statusaffected
Version0:1.6-3.el8_6.2
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat Enterprise Linux 8.6 Update Services for SAP Solutions
Default Statusaffected
Version0:1.6-3.el8_6.2
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat Enterprise Linux 8.8 Telecommunications Update Service
Default Statusaffected
Version0:1.6-6.el8_8.4
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Default Statusaffected
Version0:1.6-6.el8_8.4
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat Enterprise Linux 9
Default Statusaffected
Version0:1.6-19.el9_7.0.2
Version <*
Statusunaffected
Version0:1.6-19.el9_8.2
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat Enterprise Linux 9.0 Update Services for SAP Solutions
Default Statusaffected
Version0:1.6-12.el9_0.3
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Default Statusaffected
Version0:1.6-15.el9_2.3
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat Enterprise Linux 9.4 Extended Update Support
Default Statusaffected
Version0:1.6-16.el9_4.2
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat Enterprise Linux 9.6 Extended Update Support
Default Statusaffected
Version0:1.6-17.el9_6.4
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat OpenShift Container Platform 4.12
Default Statusaffected
Version412.86.202606140301-0
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat OpenShift Container Platform 4.13
Default Statusaffected
Version413.92.202606160406-0
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat OpenShift Container Platform 4.14
Default Statusaffected
Version414.92.202606231112-0
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat OpenShift Container Platform 4.15
Default Statusaffected
Version415.92.202606030318-0
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat OpenShift Container Platform 4.16
Default Statusaffected
Version416.94.202606051757-0
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat OpenShift Container Platform 4.17
Default Statusaffected
Version417.94.202606250942-0
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat OpenShift Container Platform 4.18
Default Statusaffected
Version418.94.202606051320-0
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat OpenShift Container Platform 4.19
Default Statusaffected
Version4.19.9.6.202606031700-0
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat AI Inference Server 3.2
Default Statusaffected
Version1780681984
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat AI Inference Server 3.3
Default Statusaffected
Version1782352950
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat AI Inference Server 3.3
Default Statusaffected
Version1782352919
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat AI Inference Server 3.3
Default Statusaffected
Version1782353093
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat AI Inference Server 3.3
Default Statusaffected
Version1782352847
Version <*
Statusunaffected
HerstellerRed Hat
≫
ProduktRed Hat Hardened Images
Default Statusaffected
Version1.8.1-3.hum1
Version <*
Statusunaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login
The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).
CWE-341 Predictable from Observable State
A number or object is predictable based on observations that the attacker can make about the state of the system or network, such as time, process ID, etc.
CWE-407 Inefficient Algorithmic Complexity
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.