CVE-2026-40553

EUVD-2026-43495
Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 21.01%
Affected Products (NVD)
VendorProductVersion
fossiesgawk
𝑥
≤ 5.4.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gawk
bookworm
vulnerable
bullseye
vulnerable
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gawk
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
resolute
Fixed 1:5.3.2-1ubuntu1.1
released
trusty
not-affected
xenial
not-affected
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
gawk
Amazon Linux 2023
0:5.1.0-3.amzn2023.0.4
fixed
gawk-all-langpacks
Amazon Linux 2023
0:5.1.0-3.amzn2023.0.4
fixed
gawk-debuginfo
Amazon Linux 2023
0:5.1.0-3.amzn2023.0.4
fixed
gawk-debugsource
Amazon Linux 2023
0:5.1.0-3.amzn2023.0.4
fixed
gawk-devel
Amazon Linux 2023
0:5.1.0-3.amzn2023.0.4
fixed
gawk-doc
Amazon Linux 2023
0:5.1.0-3.amzn2023.0.4
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
gawk
Azure Linux 3.0
0:5.2.2-2.azl3
fixed