A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.
CVSS Details
- CVSS 3.1 Base Score: 4.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade gawk-debuginfoUpgrade gawk | Dec 5, 2023 | Sep 25, 2023 |
| Amazon_linux_2023 | — | Upgrade gawkUpgrade gawk-develUpgrade gawk-all-langpacksUpgrade gawk-docUpgrade gawk-debugsourceUpgrade gawk-debuginfo | Feb 17, 2025 | Jun 19, 2023 |
| Debian | — | Upgrade gawk | Jul 30, 2024 | Sep 25, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade gawk | Jan 10, 2024 | Sep 25, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade gawk | Jan 10, 2024 | Sep 25, 2023 |
| Huawei Euleros 2_0_sp9 | — | Upgrade gawk | Jan 10, 2024 | Sep 25, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 25, 2023 |
| Suse | — | Upgrade gawk | Aug 28, 2023 | Aug 24, 2023 |
| Ubuntu | — | Upgrade gawkUpgrade gawk (Ubuntu Pro) | Sep 18, 2023 | Sep 14, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Sep 25, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub