VDB

CVE-2026-40553

CVE-2026-40553 PUBLISHED CVSS 5.1 MEDIUM

Reported by CERT-PL · Published July 13, 2026

Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.

Risk Scores

CVSS 4.0
5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L

Affected Products

VendorProductVersions
GNUgawk0
GNUgawk0

Timeline

  • Jul 13, 2026 Coalition ESS Score
  • Jul 13, 2026 CVE Published
  • Jul 13, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score

References

  • patch
  • third-party-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›