CVE-2026-6843

ADVISORY - nist

Summary

A flaw was found in nano. A local user could exploit a format string vulnerability in the statusline() function. By creating a directory with a name containing printf specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This results in a Denial of Service (DoS) for the nano application.

EPSS Score: 0.00019 (0.056)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Use of Externally-Controlled Format String


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in