Описание
Security update for gawk
This update for gawk fixes the following issues:
- CVE-2026-40467: use-after-free in the
io.cprogram file via thedo_getline_redir()routine (bsc#1271351). - CVE-2026-40468: integer overflow in the
builtin.cprogram file (bsc#1271352). - CVE-2026-40553: buffer overflow in the
extension/readdir.cprogram file via theftype()routine (bsc#1271354).
Список пакетов
Container bci/bci-sle15-kernel-module-devel:latest
Container bci/spack:latest
Container suse/kiosk/xorg-client:latest
Container suse/manager/4.3/proxy-httpd:latest
Container suse/mariadb:latest
Container suse/sle-micro-rancher/5.3:latest
Container suse/sle-micro-rancher/5.4:latest
Container suse/sle-micro/5.3/toolbox:latest
Container suse/sle-micro/5.4/toolbox:latest
Container suse/sle-micro/5.5/toolbox:latest
Container suse/sle-micro/5.5:latest
Container suse/sle-micro/base-5.5:latest
Container suse/sle-micro/kvm-5.5:latest
Container suse/sle-micro/rt-5.5:latest
Container third-party/nvidia/driver:550-sles15.7
Container third-party/nvidia/driver:570-sles15.7
Container third-party/nvidia/driver:575-sles15.7
Container third-party/nvidia/driver:580-sles15.7
Container third-party/nvidia/driver:590-sles15.7
Container third-party/nvidia/driver:595-sles15.7
SUSE Linux Enterprise Micro 5.3
SUSE Linux Enterprise Micro 5.4
SUSE Linux Enterprise Micro 5.5
SUSE Linux Enterprise Module for Basesystem 15 SP7
Ссылки
- Link for SUSE-SU-2026:3455-1
- E-Mail link for SUSE-SU-2026:3455-1
- SUSE Security Ratings
- SUSE Bug 1271351
- SUSE Bug 1271352
- SUSE Bug 1271354
- SUSE CVE CVE-2026-40467 page
- SUSE CVE CVE-2026-40468 page
- SUSE CVE CVE-2026-40553 page
Описание
Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.
Затронутые продукты
Ссылки
- CVE-2026-40467
- SUSE Bug 1271351
- SUSE Bug 1271352
- SUSE Bug 1271353
- SUSE Bug 1271354
Описание
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
Затронутые продукты
Ссылки
- CVE-2026-40468
- SUSE Bug 1271352
Описание
Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
Затронутые продукты
Ссылки
- CVE-2026-40553
- SUSE Bug 1271354