Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6390

Опубликовано: 22 июл. 2026
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.

Отчет

A format string vulnerability in GNU nano's multi-buffer error handling can lead to information disclosure, denial of service, or potentially arbitrary memory writes. This flaw occurs when a user opens multiple files at startup, and one triggers an ALERT-level error, combined with a filename containing printf format specifiers. The vulnerability affects nano versions 5.7 through 8.7 when compiled with multi-buffer support and without the NANO_TINY option.

Меры по смягчению последствий

Users should avoid opening untrusted files with GNU nano, especially those with filenames containing printf format specifiers (e.g., %s, %p, %n). This operational control helps prevent the exploitation of the format string vulnerability, which relies on specific filename content and error conditions during multi-buffer usage.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nanoFix deferred
Red Hat Enterprise Linux 6nanoFix deferred
Red Hat Enterprise Linux 7nanoFix deferred
Red Hat Enterprise Linux 8nanoFix deferred
Red Hat Enterprise Linux 9nanoFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-134
https://bugzilla.redhat.com/show_bug.cgi?id=2458767nano: GNU nano: Arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling.

EPSS

Процентиль: 1%
0.00107
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
10 дней назад

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.

CVSS3: 6.8
nvd
10 дней назад

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.

msrc
8 дней назад

Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling.

CVSS3: 6.8
debian
10 дней назад

A flaw was found in GNU nano's multi-buffer error message handling. Wh ...

CVSS3: 6.8
github
9 дней назад

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.

EPSS

Процентиль: 1%
0.00107
Низкий

6.8 Medium

CVSS3