Описание
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
A flaw was found in gawk. An integer overflow vulnerability exists in the do_sub() routine, which could allow an attacker to overwrite internal program data. This can lead to a denial of service (DoS) by causing the gawk program to crash. This issue affects 32-bit builds of gawk.
Отчет
This vulnerability is only present in 32-bit builds of gawk, which are not provided for Red Hat CoreOS, Red Hat Enterprise Linux versions 7 and later.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | gawk | Not affected | ||
| Red Hat Enterprise Linux 6 | gawk | Out of support scope | ||
| Red Hat Enterprise Linux 7 | gawk | Not affected | ||
| Red Hat Enterprise Linux 8 | gawk | Not affected | ||
| Red Hat Enterprise Linux 9 | gawk | Not affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | ||
| Red Hat Hardened Images | gawk-main-5.4.0-3.1.hum1 | Fixed | RHSA-2026:40041 | 15.07.2026 |
| Red Hat Hardened Images | gawk-main-5.4.1-1.hum1 | Fixed | RHSA-2026:49661 | 03.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
2.8 Low
CVSS3
Связанные уязвимости
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
Integer overflow vulnerability has been found in "builtin.c" program f ...
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
EPSS
2.8 Low
CVSS3