Heap buffer overflow in gawk
Published Jul 13, 2026
2.1
LOWCVSS 4.0
EPSS 0.35%
Description
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
Affected products
-
- Version 0StatusaffectedConstraints<=5.4.0
- Version
No data.
Red Hat Hardened Images
gawk-main-5.4.0-3.1.hum1
Fixed · RHSA-2026:40041
Red Hat Hardened Images
gawk-main-5.4.1-1.hum1
Fixed · RHSA-2026:49661
Red Hat Enterprise Linux 10
gawk
Affected
Red Hat Enterprise Linux 6
gawk
Out of support scope
Red Hat Enterprise Linux 7
gawk
Affected
Red Hat Enterprise Linux 8
gawk
Affected
Red Hat Enterprise Linux 9
gawk
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | gawk-main-5.4.0-3.1.hum1 | Fixed | RHSA-2026:40041 |
| Red Hat Hardened Images | gawk-main-5.4.1-1.hum1 | Fixed | RHSA-2026:49661 |
| Red Hat Enterprise Linux 10 | gawk | Affected | n/a |
| Red Hat Enterprise Linux 6 | gawk | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | gawk | Affected | n/a |
| Red Hat Enterprise Linux 8 | gawk | Affected | n/a |
| Red Hat Enterprise Linux 9 | gawk | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Moderate: An integer overflow vulnerability in gawk's builtin.c could allow a local attacker to cause memory exhaustion and overwrite heap metadata. This could lead to system instability or a denial of service on affected Red Hat products, requiring local access to execute a malicious gawk script.
Red Hat mitigation
Do not execute untrusted awk scripts or process untrusted inputs that could trigger oversized calculations in builtin.c.
Metrics
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L
1 other source (NVD) ▾
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jul 13, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jul–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.35% (0.00353) | 26.58th | v5 (v2026.06.15) |
| Jul 14, 2026 | 0.20% (0.00201) | 10.07th | v5 (v2026.06.15) |
References (6)
- https://access.redhat.com/security/cve/CVE-2026-40468 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2499655 Issue Tracking
- https://cert.pl/en/posts/2026/07/CVE-2026-40467 third-party-advisoryThird Party Advisory
- https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7 patch
- https://nvd.nist.gov/vuln/detail/CVE-2026-40468
- https://www.cve.org/CVERecord?id=CVE-2026-40468
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-40468 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2499655 | Issue Tracking | |
| https://cert.pl/en/posts/2026/07/CVE-2026-40467 | third-party-advisoryThird Party Advisory | |
| https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7 | patch | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-40468 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-40468 |
Change history (0)
No recorded changes yet.