Back

MEDIUM

Heap buffer overflow in gawk

Published Jul 13, 2026

Description

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.

Affected products

Remediation

Red Hat statement

This vulnerability is only present in 32-bit builds of gawk, which are not provided for Red Hat CoreOS, Red Hat Enterprise Linux versions 7 and later.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERT-PL
Published Jul 13, 2026
Updated Jul 13, 2026
Reserved Apr 13, 2026
CISA Vulnrichment
Updated Jul 13, 2026
NVD
Status Analyzed
Modified Jul 14, 2026
Red Hat
Severity Moderate
Public date Jul 13, 2026
ENISA EUVD
Assigner CERT-PL
Published Jul 13, 2026
Updated Jul 13, 2026
Exploited since n/a
EUVD-2026-43494