yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-4156
Component Overview
Vulnerability Overview
Name
CVE-2023-4156
Source
NVD (
link
)
Debian (
link
)
Description
A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.
CWEs
CWE-125
CWE-125
Published Date
Sep 25, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://access.redhat.com/security/cve/CVE-2023-4156
Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=2215930
Exploit
https://access.redhat.com/security/cve/CVE-2023-4156
Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=2215930
Exploit
Analysis
#
Affected Component
Analysis
gawk
Patched
Vulnerability Ratings
#
4.4
CVSSv31
7.1
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
gawk
yocto
master
5.4.0
Not Affected
gawk
yocto
scarthgap
5.3.0
Not Affected
Resolved with patches
#
gawk (yocto:kirkstone)
#
Title
Author
Resolve
1
Smal bug fix in builtin.c.
"Arnold D. Robbins" <arnold@skeeve.com>
CVE-2023-4156