View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2025-49014 severity important: SUSE including 6 source package names (jq, jq-1.8.1-1.1, libjq-devel, libjq-devel-1.8.1-1.1, libjq1, libjq1-1.8.1-1.1), 74 product×package rows across 29 product lines (SLES-LTSS-TERADATA 15 SP2, SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS, … (29 product lines)): Known Not Affected 71, Fixed 3.
jq is a command-line JSON processor. In version 1.8.0 a heap use after free vulnerability exists within the function f_strflocaltime of /src/builtin.c. This issue has been patched in commit 499c91b, no known fix version exists at time of publication.