Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
References
| Link | Resource |
|---|---|
| https://cert.pl/en/posts/2026/07/CVE-2026-40467 | Third Party Advisory |
| https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843 | Patch |
Configurations
History
14 Jul 2026, 01:10
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CPE | cpe:2.3:a:fossies:gawk:*:*:*:*:*:*:*:* | |
| First Time |
Fossies
Fossies gawk |
|
| References | () https://cert.pl/en/posts/2026/07/CVE-2026-40467 - Third Party Advisory | |
| References | () https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843 - Patch |
13 Jul 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-13 13:16
Updated : 2026-07-14 01:10
NVD link : CVE-2026-40553
Mitre link : CVE-2026-40553
CVE.ORG link : CVE-2026-40553
JSON object : View
Products Affected
fossies
- gawk
CWE
CWE-121
Stack-based Buffer Overflow
