Source: gawk Version: 1:5.3.2-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for gawk. CVE-2026-40467[0]: | Use After Free vulnerability has been found in "io.c" program file | of gawk (do_getline_redir() routine). This issue may lead to a | crash. It affects gawk in versions 5.4.0 and below. CVE-2026-40468[1]: | Integer overflow vulnerability has been found in "builtin.c" program | file of gawk. This issue may lead to memory exhaustion on the | hosting operating system and could be used to overwrite gawk heap | metadata and objects with attacker-controlled bytes. It affects gawk | in versions 5.4.0 and below. CVE-2026-40469[2]: | Integer overflow vulnerability has been found in "builtin.c" program | file of gawk (do_sub() routine). This issue could be used to | overwrite gawk heap metadata and objects causing the program to | crash. It affects 32-bit builds of gawk in versions 5.4.0 and below. CVE-2026-40553[3]: | Buffer overflow vulnerability has been found in | "extension/readdir.c" program file of gawk (ftype() routine). This | issue could be used to crash the program and potentially to achieve | code execution, although the latter has not been confirmed to be | feasible. It affects gawk in versions 5.4.0 and below. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-40467 https://www.cve.org/CVERecord?id=CVE-2026-40467 [1] https://security-tracker.debian.org/tracker/CVE-2026-40468 https://www.cve.org/CVERecord?id=CVE-2026-40468 [2] https://security-tracker.debian.org/tracker/CVE-2026-40469 https://www.cve.org/CVERecord?id=CVE-2026-40469 [3] https://security-tracker.debian.org/tracker/CVE-2026-40553 https://www.cve.org/CVERecord?id=CVE-2026-40553 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

