CVE-2026-40468

Name
CVE-2026-40468
Description
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cvd@cert.pl https://cert.pl/en/posts/2026/07/CVE-2026-40467
cvd@cert.pl https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:fossies:gawk:*:*:*:*:*:*:*:* gawk >= None <= 5.4.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
gawk edge-main 5.3.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
gawk edge-main 5.3.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
gawk edge-main 5.3.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
gawk edge-main 5.3.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
gawk 3.24-main 5.3.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
gawk 3.23-main 5.3.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
gawk 3.22-main 5.3.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
gawk 3.21-main 5.3.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
gawk 3.20-main 5.3.0-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
gawk 3.19-main 5.3.0-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable