Описание
Security update for gawk
This update for gawk fixes the following issues:
- CVE-2026-40467: use-after-free vulnerability within the do_getline_redir() routine could lead to a program crash (bsc#1271351).
- CVE-2026-40468: use-after-free vulnerability in gawk's "io.c" file could permit heap metadata manipulation and host memory exhaustion (bsc#1271352).
- CVE-2026-40553: buffer overflow in the ftype() routine of the readdir extension could trigger a program crash (bsc#1271354).
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1271351
- SUSE Bug 1271352
- SUSE Bug 1271354
- SUSE CVE CVE-2026-40467 page
- SUSE CVE CVE-2026-40468 page
- SUSE CVE CVE-2026-40553 page
Описание
Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.
Затронутые продукты
Ссылки
- CVE-2026-40467
- SUSE Bug 1271351
- SUSE Bug 1271352
- SUSE Bug 1271353
- SUSE Bug 1271354
Описание
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
Затронутые продукты
Ссылки
- CVE-2026-40468
- SUSE Bug 1271352
Описание
Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
Затронутые продукты
Ссылки
- CVE-2026-40553
- SUSE Bug 1271354