Back

LOW

Heap buffer overflow in gawk

Published Jul 13, 2026

Description

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.

Affected products

Remediation

Red Hat statement

Moderate: An integer overflow vulnerability in gawk's builtin.c could allow a local attacker to cause memory exhaustion and overwrite heap metadata. This could lead to system instability or a denial of service on affected Red Hat products, requiring local access to execute a malicious gawk script.

Red Hat mitigation

Do not execute untrusted awk scripts or process untrusted inputs that could trigger oversized calculations in builtin.c.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERT-PL
Published Jul 13, 2026
Updated Jul 13, 2026
Reserved Apr 13, 2026
CISA Vulnrichment
Updated Jul 13, 2026
NVD
Status Analyzed
Modified Jul 14, 2026
Red Hat
Severity Moderate
Public date Jul 13, 2026