CVE-2015-8863

critical
Published 2016-05-06 · Modified 2026-05-06
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
10.0
VIR risk
9.8

Description

Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-8863

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — https://github.com/stedolan/jq/commit/8eb1367ca44e772963e704a700ef72ae2e12babd

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.5+dfsg-1.1
debian debianbullseyefixed1.5+dfsg-1.1
debian debianforkyfixed1.5+dfsg-1.1
debian debiansidfixed1.5+dfsg-1.1
debian debiantrixiefixed1.5+dfsg-1.1
suse suse42.1affected
suse suse13.2affected

Application impact

VendorProductVersionsFixed
jq_projectjq{"endIncluding":"1.5"}

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.