OESA-2026-3163

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3163
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3163.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3163
Upstream
  • CVE-2026-40467
  • CVE-2026-40468
  • CVE-2026-40553
Published
2026-07-24T03:30:44Z
Modified
2026-07-24T03:45:18.669041711Z
Summary
gawk security update
Details

The gawk package is the GNU implementation of awk. The awk utility interprets a special-purpose programming language that makes it possible to handle simple data-reformatting jobs with just a few lines of code.

Security Fix(es):

Use After Free vulnerability has been found in "io.c" program file of gawk (dogetlineredir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.(CVE-2026-40467)

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.(CVE-2026-40468)

Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.(CVE-2026-40553)

Database specific
{
    "severity": "Critical"
}
References

Affected packages

openEuler:22.03-LTS-SP4 / gawk

Package

Name
gawk
Purl
pkg:rpm/openEuler/gawk&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.1.1-6.oe2203sp4

Ecosystem specific

{
    "x86_64": [
        "gawk-5.1.1-6.oe2203sp4.x86_64.rpm",
        "gawk-debuginfo-5.1.1-6.oe2203sp4.x86_64.rpm",
        "gawk-debugsource-5.1.1-6.oe2203sp4.x86_64.rpm",
        "gawk-devel-5.1.1-6.oe2203sp4.x86_64.rpm",
        "gawk-lang-5.1.1-6.oe2203sp4.x86_64.rpm"
    ],
    "src": [
        "gawk-5.1.1-6.oe2203sp4.src.rpm"
    ],
    "noarch": [
        "gawk-help-5.1.1-6.oe2203sp4.noarch.rpm"
    ],
    "aarch64": [
        "gawk-5.1.1-6.oe2203sp4.aarch64.rpm",
        "gawk-debuginfo-5.1.1-6.oe2203sp4.aarch64.rpm",
        "gawk-debugsource-5.1.1-6.oe2203sp4.aarch64.rpm",
        "gawk-devel-5.1.1-6.oe2203sp4.aarch64.rpm",
        "gawk-lang-5.1.1-6.oe2203sp4.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3163.json"