gawk-4.2.1-5.el8_10
エラータID: AXSA:2026-1956:01
The gawk packages contain the GNU version of awk, a text processing utility. Awk interprets a special-purpose programming language to do quick and easy text pattern matching and reformatting jobs.
Security Fix(es):
* gawk: gawk: Memory corruption via integer overflow (CVE-2026-40468)
* gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c (CVE-2026-40467)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-40467
Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.
CVE-2026-40468
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
Update packages.
Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.
N/A
SRPMS
- gawk-4.2.1-5.el8_10.src.rpm
MD5: 1176c6074c70f175439701e992579902
SHA-256: ccc6c50c5e6eac34a09aa15fb22baab61688e0ffdfd6e331bf02250af7564b69
Size: 2.90 MB
Asianux Server 8 for x86_64
- gawk-4.2.1-5.el8_10.x86_64.rpm
MD5: eb957a8101b660977458b16f720f1aeb
SHA-256: 2949327dbc6bc29af0bf3e0c09f545b0b75df85932964d789a134e486e995b17
Size: 1.13 MB