[CLSA-2026:1784217991] gawk: Fix of 3 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-16 16:06:58 UTC
Description:
- CVE-2026-40467: fix use-after-free in do_getline_redir() in io.c (redir_exp dereferenced after being freed) - CVE-2026-40553: fix stack buffer overflow in ftype() in the readdir extension (unbounded path concatenation before stat()) - CVE-2026-40469: fix integer overflow in do_sub() in builtin.c (64-bit overflow check on the result-buffer size prevents heap corruption in sub/gsub/gensub replacement expansion on 32-bit builds)
Updated packages:
  • gawk-5.1.0-6.el9.tuxcare.els2.x86_64.rpm
    sha:0fe70fb62f26abd6a886b72e66f02e787131f20baebe1f452ef65d18cd7f7803
  • gawk-all-langpacks-5.1.0-6.el9.tuxcare.els2.x86_64.rpm
    sha:7997bb95bca9bec1848fbead7d71427f1d39a49fba5379ba1384cdc44c93b499
  • gawk-devel-5.1.0-6.el9.tuxcare.els2.x86_64.rpm
    sha:925175b2d9fc95e7a683496bda31c8c0b093d11ccdaa9ec6a12d0770b3a4f6bc
  • gawk-doc-5.1.0-6.el9.tuxcare.els2.noarch.rpm
    sha:c013408c9f7c28d62bdc0a82ad5de4e9117460022ad2b4b7bbd9a7e862ac9155
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.