CVE-2026-40468

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fossies:gawk:*:*:*:*:*:*:*:*

History

14 Jul 2026, 01:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CPE cpe:2.3:a:fossies:gawk:*:*:*:*:*:*:*:*
First Time Fossies
Fossies gawk
References () https://cert.pl/en/posts/2026/07/CVE-2026-40467 - () https://cert.pl/en/posts/2026/07/CVE-2026-40467 - Third Party Advisory
References () https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7 - () https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7 - Patch

13 Jul 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-13 13:16

Updated : 2026-07-14 01:12


NVD link : CVE-2026-40468

Mitre link : CVE-2026-40468

CVE.ORG link : CVE-2026-40468


JSON object : View

Products Affected

fossies

  • gawk
CWE
CWE-190

Integer Overflow or Wraparound