Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
References
| Link | Resource |
|---|---|
| https://cert.pl/en/posts/2026/07/CVE-2026-40467 | Third Party Advisory |
| https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7 | Patch |
Configurations
History
14 Jul 2026, 01:12
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
| CPE | cpe:2.3:a:fossies:gawk:*:*:*:*:*:*:*:* | |
| First Time |
Fossies
Fossies gawk |
|
| References | () https://cert.pl/en/posts/2026/07/CVE-2026-40467 - Third Party Advisory | |
| References | () https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7 - Patch |
13 Jul 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-13 13:16
Updated : 2026-07-14 01:12
NVD link : CVE-2026-40468
Mitre link : CVE-2026-40468
CVE.ORG link : CVE-2026-40468
JSON object : View
Products Affected
fossies
- gawk
CWE
CWE-190
Integer Overflow or Wraparound
