Heap buffer overflow in gawk
Published Jul 13, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.35%
Description
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
Affected products
-
- Version 0StatusaffectedConstraints<=5.4.0
- Version
No data.
Red Hat Hardened Images
gawk-main-5.4.0-3.1.hum1
Fixed · RHSA-2026:40041
Red Hat Hardened Images
gawk-main-5.4.1-1.hum1
Fixed · RHSA-2026:49661
Red Hat Enterprise Linux 10
gawk
Not affected
Red Hat Enterprise Linux 6
gawk
Out of support scope
Red Hat Enterprise Linux 7
gawk
Not affected
Red Hat Enterprise Linux 8
gawk
Not affected
Red Hat Enterprise Linux 9
gawk
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | gawk-main-5.4.0-3.1.hum1 | Fixed | RHSA-2026:40041 |
| Red Hat Hardened Images | gawk-main-5.4.1-1.hum1 | Fixed | RHSA-2026:49661 |
| Red Hat Enterprise Linux 10 | gawk | Not affected | n/a |
| Red Hat Enterprise Linux 6 | gawk | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | gawk | Not affected | n/a |
| Red Hat Enterprise Linux 8 | gawk | Not affected | n/a |
| Red Hat Enterprise Linux 9 | gawk | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is only present in 32-bit builds of gawk, which are not provided for Red Hat CoreOS, Red Hat Enterprise Linux versions 7 and later.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-40469 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2499656 Issue Tracking
- https://cert.pl/en/posts/2026/07/CVE-2026-40467 third-party-advisoryThird Party Advisory
- https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=ae1b2d508f46913269a9e62aceda3636afe8147b patch
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43494 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-40469
- https://www.cve.org/CVERecord?id=CVE-2026-40469
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-40469 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2499656 | Issue Tracking | |
| https://cert.pl/en/posts/2026/07/CVE-2026-40467 | third-party-advisoryThird Party Advisory | |
| https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=ae1b2d508f46913269a9e62aceda3636afe8147b | patch | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43494 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-40469 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-40469 |
Change history (0)
No recorded changes yet.