Logo
vulnerabilityCVE-2026-40469
Name
CVE-2026-40469
Source
NVD ( link)Debian ( link)
Description
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
gawk
Patched

Vulnerability Ratings#


5.1
CVSSv4
9.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
5.1.1
Exploitable
yocto
master
5.4.1
Not Affected

Resolved with patches#


gawk (yocto:scarthgap)

#
Title
Author
Resolve
1
Add overflow checking in do_sub for 32 bit systems.
"Arnold D. Robbins" <arnold@skeeve.com>
CVE-2026-40469