CVE-2026-40468
published 2026-07-13CVE-2026-40468: Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and…
PriorityP352critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
0.20%
10.1th percentile
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fossies | gawk | <= 5.4.0 | — |
| gnu | gawk | <= 5.4.0 | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv4.02.1LOWCVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GNU gawk up to 5.4.0 builtin.c integer overflow (Nessus ID 326566)
vuldb·2026-07-14·CVSS 9.1
CVE-2026-40468 [CRITICAL] GNU gawk up to 5.4.0 builtin.c integer overflow (Nessus ID 326566)
A vulnerability classified as problematic has been found in GNU gawk up to 5.4.0. Impacted is an unknown function of the file builtin.c. This manipulation causes integer overflow.
This vulnerability is tracked as CVE-2026-40468. The attack is restricted to local execution. No exploit exists.
GHSA
Integer overflow vulnerability has been found in "builtin.c" program file of gawk.
ghsa_unreviewed·2026-07-13
CVE-2026-40468 [LOW] CWE-190 Integer overflow vulnerability has been found in "builtin.c" program file of gawk.
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
No detection rules found.
No public exploits indexed.
2026-07-13
Published