Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
CVSS Details
- CVSS 4.0 Base Score: 2.1 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade gawkUpgrade gawk-develUpgrade gawk-docUpgrade gawk-debuginfoUpgrade gawk-all-langpacksUpgrade gawk-debugsource | Aug 10, 2026 | Jul 13, 2026 |
| Redhat_linux | — | Upgrade gawkNo solution existsUpgrade gawk-debuginfoUpgrade gawk-all-langpacksUpgrade gawk-debugsource | Aug 4, 2026 | Jul 13, 2026 |
| Ubuntu | — | Upgrade gawk (Ubuntu Pro)Upgrade gawk | Jul 23, 2026 | Jul 22, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 31, 2026 | Jul 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub