gawk-5.1.0-6.el9_8.1
エラータID: AXSA:2026-1965:02
The gawk packages contain the GNU version of awk, a text processing utility. Awk interprets a special-purpose programming language to do quick and easy text pattern matching and reformatting jobs.
Security Fix(es):
* gawk: gawk: Memory corruption via integer overflow (CVE-2026-40468)
* gawk: Gawk: Buffer overflow in ftype() routine may lead to code execution or denial of service (CVE-2026-40553)
* gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c (CVE-2026-40467)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-40467
Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.
CVE-2026-40468
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
CVE-2026-40553
Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
Update packages.
Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
N/A
SRPMS
- gawk-5.1.0-6.el9_8.1.src.rpm
MD5: 224beb71b62d9e7c4bc5f66a3d0c76f6
SHA-256: 6294375a56706932438d5e2391d018488fe1e5234bdd7faf3b4f1637cf332e2d
Size: 3.04 MB
Asianux Server 9 for x86_64
- gawk-5.1.0-6.el9_8.1.x86_64.rpm
MD5: 3664315666c625ca36ce2c1f4632ab78
SHA-256: b28c456d7809d425d63a218d36b41175b141169ef3de2a5f7eaa8cf26c65acbf
Size: 0.99 MB - gawk-all-langpacks-5.1.0-6.el9_8.1.x86_64.rpm
MD5: f7eb6742f602fc85300cadc0f66c2992
SHA-256: f2b5468b2bdf78ee7460bf28032feecbead60cad2099fd23ce1a4ce6122b12d3
Size: 210.76 kB