CVE-2026-6390

Published: July 24, 2026Last modified: July 31, 2026

Description

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.

Severity score breakdown

ParameterValue
Base score6.8
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSnanoVulnerable (7.0-r0)
25 LTSnanoVulnerable (8.4-r0)
StreamnanoVulnerable (7.0-r0)

References

ON THIS PAGE