Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40468

Опубликовано: 13 июл. 2026
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.

A flaw was found in gawk. An integer overflow vulnerability could allow a local attacker to cause memory exhaustion, leading to a denial of service. This flaw may also enable an attacker to corrupt gawk's internal memory, potentially leading to system instability.

Отчет

Moderate: An integer overflow vulnerability in gawk's builtin.c could allow a local attacker to cause memory exhaustion and overwrite heap metadata. This could lead to system instability or a denial of service on affected Red Hat products, requiring local access to execute a malicious gawk script.

Меры по смягчению последствий

Do not execute untrusted awk scripts or process untrusted inputs that could trigger oversized calculations in builtin.c.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gawkAffected
Red Hat Enterprise Linux 6gawkOut of support scope
Red Hat Enterprise Linux 7gawkAffected
Red Hat Enterprise Linux 8gawkAffected
Red Hat Enterprise Linux 9gawkAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Hardened Imagesgawk-main-5.4.0-3.1.hum1FixedRHSA-2026:4004115.07.2026
Red Hat Hardened Imagesgawk-main-5.4.1-1.hum1FixedRHSA-2026:4966103.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2499655gawk: gawk: Memory corruption via integer overflow

EPSS

Процентиль: 10%
0.00201
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
24 дня назад

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.

CVSS3: 9.1
nvd
24 дня назад

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.

msrc
24 дня назад

Heap buffer overflow in gawk

CVSS3: 9.1
debian
24 дня назад

Integer overflow vulnerability has been found in "builtin.c" program f ...

suse-cvrf
14 дней назад

Security update for gawk

EPSS

Процентиль: 10%
0.00201
Низкий

4.4 Medium

CVSS3