CVE-2026-40469

NameCVE-2026-40469
DescriptionInteger overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1142071

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gawk (PTS)bullseye1:5.1.0-1vulnerable
bookworm, trixie1:5.2.1-2vulnerable
forky, sid1:5.3.2-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gawksource(unstable)(unfixed)1142071

Notes

Fixed by: https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=ae1b2d508f46913269a9e62aceda3636afe8147b

Search for package or bug name: Reporting problems