Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40467

Опубликовано: 13 июл. 2026
Источник: redhat
CVSS3: 4

Описание

Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.

A flaw was found in gawk. A Use After Free vulnerability exists in the do_getline_redir() routine within the io.c program file. This vulnerability can be triggered by an attacker, potentially leading to a system crash and causing a Denial of Service (DoS).

Отчет

Moderate: A Use After Free vulnerability in gawk's do_getline_redir() routine can lead to a denial of service. This flaw, affecting gawk in Red Hat Hardened Images, requires a local attacker with low privileges to trick a user into interacting with specially crafted input, limiting its immediate impact.

Меры по смягчению последствий

To mitigate this issue, users should avoid processing untrusted or maliciously crafted input with gawk. Exercise caution when executing gawk scripts or commands that process data from unknown or unverified sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gawkAffected
Red Hat Enterprise Linux 6gawkOut of support scope
Red Hat Enterprise Linux 7gawkAffected
Red Hat Enterprise Linux 8gawkAffected
Red Hat Enterprise Linux 9gawkAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Hardened Imagesgawk-main-5.4.0-3.1.hum1FixedRHSA-2026:4004115.07.2026
Red Hat Hardened Imagesgawk-main-5.4.1-1.hum1FixedRHSA-2026:4966103.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2499658gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
24 дня назад

Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.

CVSS3: 7.5
nvd
24 дня назад

Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.

msrc
24 дня назад

Use after free in gawk

CVSS3: 7.5
debian
24 дня назад

Use After Free vulnerability has been found in "io.c" program file of ...

CVSS3: 7.5
github
24 дня назад

Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.

4 Medium

CVSS3