Описание
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
A flaw was found in gawk. An integer overflow vulnerability could allow a local attacker to cause memory exhaustion, leading to a denial of service. This flaw may also enable an attacker to corrupt gawk's internal memory, potentially leading to system instability.
Отчет
Moderate: An integer overflow vulnerability in gawk's builtin.c could allow a local attacker to cause memory exhaustion and overwrite heap metadata. This could lead to system instability or a denial of service on affected Red Hat products, requiring local access to execute a malicious gawk script.
Меры по смягчению последствий
Do not execute untrusted awk scripts or process untrusted inputs that could trigger oversized calculations in builtin.c.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | gawk | Affected | ||
| Red Hat Enterprise Linux 6 | gawk | Out of support scope | ||
| Red Hat Enterprise Linux 7 | gawk | Affected | ||
| Red Hat Enterprise Linux 8 | gawk | Affected | ||
| Red Hat Enterprise Linux 9 | gawk | Affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Affected | ||
| Red Hat Hardened Images | gawk-main-5.4.0-3.1.hum1 | Fixed | RHSA-2026:40041 | 15.07.2026 |
| Red Hat Hardened Images | gawk-main-5.4.1-1.hum1 | Fixed | RHSA-2026:49661 | 03.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.4 Medium
CVSS3
Связанные уязвимости
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
Integer overflow vulnerability has been found in "builtin.c" program f ...
EPSS
4.4 Medium
CVSS3