Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-6390

Опубликовано: 23 июл. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.8

Описание

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.

РелизСтатусПримечание
devel

deferred

2026-07-28
esm-infra-legacy/trusty

deferred

2026-07-28
esm-infra-legacy/xenial

deferred

2026-07-28
esm-infra/bionic

deferred

2026-07-28
esm-infra/focal

deferred

2026-07-28
jammy

deferred

2026-07-28
noble

deferred

2026-07-28
resolute

deferred

2026-07-28
upstream

deferred

2026-07-28

Показывать по

EPSS

Процентиль: 1%
0.00107
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
redhat
11 дней назад

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.

CVSS3: 6.8
nvd
10 дней назад

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.

msrc
8 дней назад

Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling.

CVSS3: 6.8
debian
10 дней назад

A flaw was found in GNU nano's multi-buffer error message handling. Wh ...

CVSS3: 6.8
github
9 дней назад

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.

EPSS

Процентиль: 1%
0.00107
Низкий

6.8 Medium

CVSS3