CVE-2026-40468

Published: July 16, 2026Last modified: July 21, 2026

Description

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.

Severity score breakdown

ParameterValue
Base score9.1
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgawkFixed (5.1.1-r2)
25 LTSgawkFixed (5.3.2-r3)
StreamgawkFixed (5.3.2-r3)
Hardened Containers23 LTSgawkFixed (5.1.1-r2)
25 LTSgawkFixed (5.3.2-r3)
StreamgawkFixed (5.3.2-r3)

References

ON THIS PAGE