Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-48060 PoC — AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt)

Source
Associated Vulnerability
Title: AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt) (CVE-2025-48060)
Description:jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_fuzz_execute harness from oss-fuzz. This crash happens on file jv.c, line 1456 `void* p = malloc(sz);`. As of time of publication, no patched versions are available.
Description
Backported the upstream fix for CVE-2025-48060 (heap buffer overflow in jv_string_empty) to jq 1.6.
Readme
# jq-els-backport-cve-2025-48060
Backported the upstream fix for CVE-2025-48060 (heap buffer overflow in jv_string_empty) to jq 1.6.

Backport (CVE-2025-48060) – Backported upstream commit c6e0416 (“Fix heap buffer overflow when formatting an empty string”) from a newer jq version to jq-1.6, adapting internal string representation (jv_string_empty), adding a regression test (0[implode]), rebuilding and running the test suite successfully.

# How to apply this patch

You can apply this backport on top of the official **jq-1.6** release either
from a tarball or from a git checkout.

## 1) Download and unpack jq-1.6
```
curl -LO https://github.com/jqlang/jq/releases/download/jq-1.6/jq-1.6.tar.gz
tar xf jq-1.6.tar.gz
cd jq-1.6
```
## 2) Copy the patch from this repo into the jq source directory

## 3) Apply the backport patch
```
patch -p1 < 0001-Fix-heap-buffer-overflow-when-formatting-an-empty-st.patch
```
## 4) Regenerate build system and build jq
```
autoreconf -i
./configure --with-oniguruma=builtin
make -j"$(nproc)"
```
## 5) Run the test suite
```
make check
```
In case you want to apply it from a git checkout:

## 1) Clone the jq repository
```
git clone https://github.com/jqlang/jq.git
cd jq
```
## 2) Switch to jq 1.6 tag
```
git checkout jq-1.6
```
## 3) Copy the patch from this repo into the jq source directory

## 4) Apply the patch with git am
```
git am 0001-Fix-heap-buffer-overflow-when-formatting-an-empty-st.patch
```
## 5) Compile and run the tests
```
git submodule update --init
autoreconf -i
./configure --with-oniguruma=builtin
make -j"$(nproc)"
make check
```

File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →