Описание
Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
A flaw was found in gawk. A buffer overflow vulnerability exists in the ftype() routine, located in the extension/readdir.c program file. This vulnerability could allow an attacker to crash the program, resulting in a denial of service. It may also potentially lead to arbitrary code execution, though this has not been definitively confirmed.
Отчет
Moderate: A buffer overflow in gawk's ftype() routine, when processing untrusted input, could lead to a denial of service or potentially arbitrary code execution. This is rated Moderate as successful exploitation requires user interaction, such as processing a specially crafted file.
Меры по смягчению последствий
Do not run gawk against untrusted scripts, files, or directories to prevent triggering these vulnerabilities. If an attack is attempted, Red Hat's built-in memory protections will safely crash the program, preventing malicious code execution.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | gawk | Affected | ||
| Red Hat Enterprise Linux 6 | gawk | Out of support scope | ||
| Red Hat Enterprise Linux 7 | gawk | Affected | ||
| Red Hat Enterprise Linux 8 | gawk | Affected | ||
| Red Hat Enterprise Linux 9 | gawk | Affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Not affected | ||
| Red Hat Hardened Images | gawk-main-5.4.0-3.1.hum1 | Fixed | RHSA-2026:40041 | 15.07.2026 |
| Red Hat Hardened Images | gawk-main-5.4.1-1.hum1 | Fixed | RHSA-2026:49661 | 03.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.2 Medium
CVSS3
Связанные уязвимости
Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
Buffer overflow vulnerability has been found in "extension/readdir.c" ...
Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
EPSS
6.2 Medium
CVSS3