CVE-2026-40468

EUVD-2026-43493
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 9.88%
Affected Products (NVD)
VendorProductVersion
fossiesgawk
𝑥
≤ 5.4.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gawk
bookworm
vulnerable
bullseye
vulnerable
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gawk
bionic
Fixed 1:4.1.4+dfsg-1ubuntu0.1~esm2
released
focal
Fixed 1:5.0.1+dfsg-1ubuntu0.1+esm1
released
jammy
Fixed 1:5.1.0-1ubuntu0.2
released
noble
Fixed 1:5.2.1-2ubuntu0.1
released
resolute
Fixed 1:5.3.2-1ubuntu1.1
released
trusty
Fixed 1:4.0.1+dfsg-2.1ubuntu2+esm2
released
xenial
Fixed 1:4.1.3+dfsg-0.1ubuntu0.1~esm2
released
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
gawk
Amazon Linux 2023
0:5.1.0-3.amzn2023.0.4
fixed
gawk-all-langpacks
Amazon Linux 2023
0:5.1.0-3.amzn2023.0.4
fixed
gawk-debuginfo
Amazon Linux 2023
0:5.1.0-3.amzn2023.0.4
fixed
gawk-debugsource
Amazon Linux 2023
0:5.1.0-3.amzn2023.0.4
fixed
gawk-devel
Amazon Linux 2023
0:5.1.0-3.amzn2023.0.4
fixed
gawk-doc
Amazon Linux 2023
0:5.1.0-3.amzn2023.0.4
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
gawk
Azure Linux 3.0
0:5.2.2-2.azl3
fixed