gawk-4.2.1-5.el8_10

エラータID: AXSA:2026-1956:01

リリース日: 
2026/10/02 Friday - 22:04
題名: 
gawk-4.2.1-5.el8_10
影響のあるチャネル: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

The gawk packages contain the GNU version of awk, a text processing utility. Awk interprets a special-purpose programming language to do quick and easy text pattern matching and reformatting jobs.

Security Fix(es):

* gawk: gawk: Memory corruption via integer overflow (CVE-2026-40468)
* gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c (CVE-2026-40467)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-40467
Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.
CVE-2026-40468
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. gawk-4.2.1-5.el8_10.src.rpm
    MD5: 1176c6074c70f175439701e992579902
    SHA-256: ccc6c50c5e6eac34a09aa15fb22baab61688e0ffdfd6e331bf02250af7564b69
    Size: 2.90 MB

Asianux Server 8 for x86_64
  1. gawk-4.2.1-5.el8_10.x86_64.rpm
    MD5: eb957a8101b660977458b16f720f1aeb
    SHA-256: 2949327dbc6bc29af0bf3e0c09f545b0b75df85932964d789a134e486e995b17
    Size: 1.13 MB