Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40553

Опубликовано: 13 июл. 2026
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.

A flaw was found in gawk. A buffer overflow vulnerability exists in the ftype() routine, located in the extension/readdir.c program file. This vulnerability could allow an attacker to crash the program, resulting in a denial of service. It may also potentially lead to arbitrary code execution, though this has not been definitively confirmed.

Отчет

Moderate: A buffer overflow in gawk's ftype() routine, when processing untrusted input, could lead to a denial of service or potentially arbitrary code execution. This is rated Moderate as successful exploitation requires user interaction, such as processing a specially crafted file.

Меры по смягчению последствий

Do not run gawk against untrusted scripts, files, or directories to prevent triggering these vulnerabilities. If an attack is attempted, Red Hat's built-in memory protections will safely crash the program, preventing malicious code execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gawkAffected
Red Hat Enterprise Linux 6gawkOut of support scope
Red Hat Enterprise Linux 7gawkAffected
Red Hat Enterprise Linux 8gawkAffected
Red Hat Enterprise Linux 9gawkAffected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Hardened Imagesgawk-main-5.4.0-3.1.hum1FixedRHSA-2026:4004115.07.2026
Red Hat Hardened Imagesgawk-main-5.4.1-1.hum1FixedRHSA-2026:4966103.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2499657gawk: Gawk: Buffer overflow in ftype() routine may lead to code execution or denial of service

EPSS

Процентиль: 21%
0.00291
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
24 дня назад

Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.

CVSS3: 7.5
nvd
24 дня назад

Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.

msrc
24 дня назад

Stack-based buffer overflow in gawk

CVSS3: 7.5
debian
24 дня назад

Buffer overflow vulnerability has been found in "extension/readdir.c" ...

CVSS3: 7.5
github
24 дня назад

Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.

EPSS

Процентиль: 21%
0.00291
Низкий

6.2 Medium

CVSS3