[CLSA-2026:1784623908] gawk: Fix of CVE-2026-40468
Type:
security
Severity:
Critical
Release date:
2026-07-21 08:52:12 UTC
Description:
- CVE-2026-40467: fix use-after-free in do_getline_redir() in io.c (redir_exp dereferenced after being freed) - CVE-2026-40553: fix stack buffer overflow in ftype() in the readdir extension (unbounded path concatenation before stat()) - CVE-2026-40469: fix integer overflow in do_sub() in builtin.c (64-bit overflow check on the result-buffer size prevents heap corruption in sub/gsub/gensub replacement expansion on 32-bit builds)
CVEs fixed:
Updated packages:
  • gawk-5.1.0-6.el9_6.tuxcare.els2.x86_64.rpm
    sha:3f7edbb9f2f4d7bb21077bcb292ce5b683a9e392caeb808c6e35e448187d60e0
  • gawk-all-langpacks-5.1.0-6.el9_6.tuxcare.els2.x86_64.rpm
    sha:7e8015d7dff4a289294b21e8909f852e65ce5d88de247c318b99c31523257918
  • gawk-devel-5.1.0-6.el9_6.tuxcare.els2.x86_64.rpm
    sha:02d1c29a8dd42bfae0c4753c323d2ff849d0e0fbb961192c4dd443c432675be8
  • gawk-doc-5.1.0-6.el9_6.tuxcare.els2.noarch.rpm
    sha:935055f7c84874fefa02ee8596ac6f5db030aa5ffa2f9fabf8a76b474ac34076
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.