CVE-2026-40553

NameCVE-2026-40553
DescriptionBuffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1142071

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gawk (PTS)bullseye1:5.1.0-1vulnerable
bookworm, trixie1:5.2.1-2vulnerable
forky, sid1:5.3.2-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gawksource(unstable)(unfixed)1142071

Notes

Fixed by: https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843

Search for package or bug name: Reporting problems