CVE-2026-40469

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fossies:gawk:*:*:*:*:*:*:*:*

History

14 Jul 2026, 01:11

Type Values Removed Values Added
References () https://cert.pl/en/posts/2026/07/CVE-2026-40467 - () https://cert.pl/en/posts/2026/07/CVE-2026-40467 - Third Party Advisory
References () https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=ae1b2d508f46913269a9e62aceda3636afe8147b - () https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=ae1b2d508f46913269a9e62aceda3636afe8147b - Patch
CPE cpe:2.3:a:fossies:gawk:*:*:*:*:*:*:*:*
First Time Fossies
Fossies gawk
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

13 Jul 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-13 13:16

Updated : 2026-07-14 01:11


NVD link : CVE-2026-40469

Mitre link : CVE-2026-40469

CVE.ORG link : CVE-2026-40469


JSON object : View

Products Affected

fossies

  • gawk
CWE
CWE-190

Integer Overflow or Wraparound