Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3455-1

Опубликовано: 03 авг. 2026
Источник: suse-cvrf

Описание

Security update for gawk

This update for gawk fixes the following issues:

  • CVE-2026-40467: use-after-free in the io.c program file via the do_getline_redir() routine (bsc#1271351).
  • CVE-2026-40468: integer overflow in the builtin.c program file (bsc#1271352).
  • CVE-2026-40553: buffer overflow in the extension/readdir.c program file via the ftype() routine (bsc#1271354).

Список пакетов

Container bci/bci-sle15-kernel-module-devel:latest
gawk-4.2.1-150000.3.6.1
Container bci/spack:latest
gawk-4.2.1-150000.3.6.1
Container suse/kiosk/xorg-client:latest
gawk-4.2.1-150000.3.6.1
Container suse/manager/4.3/proxy-httpd:latest
gawk-4.2.1-150000.3.6.1
Container suse/mariadb:latest
gawk-4.2.1-150000.3.6.1
Container suse/sle-micro-rancher/5.3:latest
gawk-4.2.1-150000.3.6.1
Container suse/sle-micro-rancher/5.4:latest
gawk-4.2.1-150000.3.6.1
Container suse/sle-micro/5.3/toolbox:latest
gawk-4.2.1-150000.3.6.1
Container suse/sle-micro/5.4/toolbox:latest
gawk-4.2.1-150000.3.6.1
Container suse/sle-micro/5.5/toolbox:latest
gawk-4.2.1-150000.3.6.1
Container suse/sle-micro/5.5:latest
gawk-4.2.1-150000.3.6.1
Container suse/sle-micro/base-5.5:latest
gawk-4.2.1-150000.3.6.1
Container suse/sle-micro/kvm-5.5:latest
gawk-4.2.1-150000.3.6.1
Container suse/sle-micro/rt-5.5:latest
gawk-4.2.1-150000.3.6.1
Container third-party/nvidia/driver:550-sles15.7
gawk-4.2.1-150000.3.6.1
Container third-party/nvidia/driver:570-sles15.7
gawk-4.2.1-150000.3.6.1
Container third-party/nvidia/driver:575-sles15.7
gawk-4.2.1-150000.3.6.1
Container third-party/nvidia/driver:580-sles15.7
gawk-4.2.1-150000.3.6.1
Container third-party/nvidia/driver:590-sles15.7
gawk-4.2.1-150000.3.6.1
Container third-party/nvidia/driver:595-sles15.7
gawk-4.2.1-150000.3.6.1
SUSE Linux Enterprise Micro 5.3
gawk-4.2.1-150000.3.6.1
SUSE Linux Enterprise Micro 5.4
gawk-4.2.1-150000.3.6.1
SUSE Linux Enterprise Micro 5.5
gawk-4.2.1-150000.3.6.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
gawk-4.2.1-150000.3.6.1

Описание

Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:gawk-4.2.1-150000.3.6.1
Container bci/spack:latest:gawk-4.2.1-150000.3.6.1
Container suse/kiosk/xorg-client:latest:gawk-4.2.1-150000.3.6.1
Container suse/manager/4.3/proxy-httpd:latest:gawk-4.2.1-150000.3.6.1

Ссылки

Описание

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:gawk-4.2.1-150000.3.6.1
Container bci/spack:latest:gawk-4.2.1-150000.3.6.1
Container suse/kiosk/xorg-client:latest:gawk-4.2.1-150000.3.6.1
Container suse/manager/4.3/proxy-httpd:latest:gawk-4.2.1-150000.3.6.1

Ссылки

Описание

Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:gawk-4.2.1-150000.3.6.1
Container bci/spack:latest:gawk-4.2.1-150000.3.6.1
Container suse/kiosk/xorg-client:latest:gawk-4.2.1-150000.3.6.1
Container suse/manager/4.3/proxy-httpd:latest:gawk-4.2.1-150000.3.6.1

Ссылки