[CLSA-2026:1784802906] gawk: Fix of CVE-2026-40468
Type:
security
Severity:
Critical
Release date:
2026-07-23 10:35:32 UTC
Description:
- CVE-2026-40468: fix integer overflows in do_sub() in builtin.c and parse_escape() in node.c (sofar widened to size_t, escape accumulator widened to int64_t to avoid overflow on 32-bit builds)
CVEs fixed:
Updated packages:
  • gawk-5.1.0-6.el9_2.tuxcare.els3.x86_64.rpm
    sha:9d291e97c3ededc1131cd59cbd6c664ced99930ea92e506de3105de72cab3a58
  • gawk-all-langpacks-5.1.0-6.el9_2.tuxcare.els3.x86_64.rpm
    sha:14df96cd1e1a03c9c8aca9a0622e7dc5b5dda2809e3c036475b30f92151c6d99
  • gawk-devel-5.1.0-6.el9_2.tuxcare.els3.x86_64.rpm
    sha:068f107368d876db6547f9f9dcc09da3f499e272e8f6b0ccbbf690ff4b52704a
  • gawk-doc-5.1.0-6.el9_2.tuxcare.els3.noarch.rpm
    sha:fc22a4fa89fa3940df1a5436b917add9eea960b5775457a273a55f68918422a2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.