CVE-2026-40553

Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fossies:gawk:*:*:*:*:*:*:*:*

History

14 Jul 2026, 01:10

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:fossies:gawk:*:*:*:*:*:*:*:*
First Time Fossies
Fossies gawk
References () https://cert.pl/en/posts/2026/07/CVE-2026-40467 - () https://cert.pl/en/posts/2026/07/CVE-2026-40467 - Third Party Advisory
References () https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843 - () https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843 - Patch

13 Jul 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-13 13:16

Updated : 2026-07-14 01:10


NVD link : CVE-2026-40553

Mitre link : CVE-2026-40553

CVE.ORG link : CVE-2026-40553


JSON object : View

Products Affected

fossies

  • gawk
CWE
CWE-121

Stack-based Buffer Overflow