Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40469

Опубликовано: 13 июл. 2026
Источник: redhat
CVSS3: 2.8
EPSS Низкий

Описание

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.

A flaw was found in gawk. An integer overflow vulnerability exists in the do_sub() routine, which could allow an attacker to overwrite internal program data. This can lead to a denial of service (DoS) by causing the gawk program to crash. This issue affects 32-bit builds of gawk.

Отчет

This vulnerability is only present in 32-bit builds of gawk, which are not provided for Red Hat CoreOS, Red Hat Enterprise Linux versions 7 and later.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gawkNot affected
Red Hat Enterprise Linux 6gawkOut of support scope
Red Hat Enterprise Linux 7gawkNot affected
Red Hat Enterprise Linux 8gawkNot affected
Red Hat Enterprise Linux 9gawkNot affected
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Hardened Imagesgawk-main-5.4.0-3.1.hum1FixedRHSA-2026:4004115.07.2026
Red Hat Hardened Imagesgawk-main-5.4.1-1.hum1FixedRHSA-2026:4966103.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2499656gawk: gawk: Denial of Service due to integer overflow

EPSS

Процентиль: 12%
0.00213
Низкий

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
24 дня назад

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.

CVSS3: 9.1
nvd
24 дня назад

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.

msrc
24 дня назад

Heap buffer overflow in gawk

CVSS3: 9.1
debian
24 дня назад

Integer overflow vulnerability has been found in "builtin.c" program f ...

CVSS3: 9.1
github
24 дня назад

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.

EPSS

Процентиль: 12%
0.00213
Низкий

2.8 Low

CVSS3