CVE-2026-40468

NameCVE-2026-40468
DescriptionInteger overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1142071

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gawk (PTS)bullseye1:5.1.0-1vulnerable
bookworm, trixie1:5.2.1-2vulnerable
forky, sid1:5.3.2-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gawksource(unstable)(unfixed)1142071

Notes

Fixed by: https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7

Search for package or bug name: Reporting problems