yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2026-40467
Component Overview
Vulnerability Overview
Name
CVE-2026-40467
Source
NVD (
link
)
Debian (
link
)
Description
Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.
CWEs
CWE-416
Published Date
Jul 13, 2026
Updated Date
Jul 14, 2026
Workaround
-
Advisories
https://cert.pl/en/posts/2026/07/CVE-2026-40467
Third Party Advisory
https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8
Patch
Analysis
#
Affected Component
Analysis
gawk
Patched
Vulnerability Ratings
#
5.1
CVSSv4
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
gawk
yocto
kirkstone
5.1.1
Exploitable
gawk
yocto
master
5.4.1
Not Affected
Resolved with patches
#
gawk (yocto:scarthgap)
#
Title
Author
Resolve
1
Small memory management fix in io.c.
"Arnold D. Robbins" <arnold@skeeve.com>
CVE-2026-40467