cbcvebase.

Gnu Nano vulnerabilities

5 known vulnerabilities affecting gnu/nano.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2LOW3

Vulnerabilities

Page 1 of 1
CVE-2024-5742P4MEDIUMCVSS 6.7≥ 2.2.0, < 8.02024-06-12
CVE-2024-5742 [MEDIUM] CWE-59 CVE-2024-5742: A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecur A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.
nvdosv
CVE-2026-6843P4MEDIUMCVSS 5.5v8.72026-04-22
CVE-2026-6843 [MEDIUM] CWE-134 CVE-2026-6843: A flaw was found in nano. A local user could exploit a format string vulnerability in the `statuslin A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This results in a Denial of Service (DoS) for the `nano` application.
nvd
CVE-2010-1161P4LOWCVSS 3.7≤ 2.2.3v0.5.0+139 more2010-04-16
CVE-2010-1161 [LOW] CWE-362 CVE-2010-1161: Race condition in GNU nano before 2.2.4, when run by root to edit a file that is not owned by root, Race condition in GNU nano before 2.2.4, when run by root to edit a file that is not owned by root, allows local user-assisted attackers to change the ownership of arbitrary files via vectors related to the creation of backup files.
nvdosv
CVE-2026-40556P4LOWCVSS 2.1≥ 2.9.1, < 9.02026-04-28
CVE-2026-40556 [LOW] CWE-732 CVE-2026-40556: GNU nano creates the user’s ~/.local directory with overly permissive permissions when the directory GNU nano creates the user’s ~/.local directory with overly permissive permissions when the directory does not exist yet. On first use of features requiring Cross-Desktop Group (XDG) data storage, nano explicitly requests directory mode 0777, making the directory world‑writable in environments where the process umask does not sufficiently restrict permi
cvelistv5nvd
CVE-2010-1160P4LOWCVSS 1.9≤ 2.2.3v0.5.0+139 more2010-04-16
CVE-2010-1160 [LOW] CWE-59 CVE-2010-1160: GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an attacker-owned file that is being edited by the victim.
nvdosv
Gnu Nano vulnerabilities | cvebase