CVE-2026-40469
ADVISORY - debianSummary
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
- gawk (bug https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142071) [trixie] - gawk (Minor issue) Fixed by: https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=ae1b2d508f46913269a9e62aceda3636afe8147b
EPSS Score: 0.00353 (0.279)
Common Weakness Enumeration (CWE)
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in