<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:42:22.551967+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:73429</id>
    <title>ALSA-2026:73429 — Moderate: gawk security update</title>
    <updated>2026-10-02T10:42:22.779460+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: gawk, AlmaLinux:10: gawk-all-langpacks</p>
<p>The gawk packages contain the GNU version of awk, a text processing utility. Awk interprets a special-purpose programming language to do quick and easy text pattern matching and reformatting jobs.</p>
<p>Security Fix(es):</p>
<p>* gawk: gawk: Memory corruption via integer overflow (CVE-2026-40468)
  * gawk: Gawk: Buffer overflow in ftype() routine may lead to code execution or denial of service (CVE-2026-40553)
  * gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c (CVE-2026-40467)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:73429"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-40467</id>
    <title>BELL-CVE-2026-40467</title>
    <updated>2026-10-02T10:42:22.779522+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: gawk, Alpaquita:25: gawk, Alpaquita:stream: gawk, BellSoft Hardened Containers:23: gawk, BellSoft Hardened Containers:25: gawk, BellSoft Hardened Containers:stream: gawk</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-40467"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335786</id>
    <title>EUVD-2026-335786</title>
    <updated>2026-10-02T10:42:22.779552+00:00</updated>
    <content>EUVD-2026-335786</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335786"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40467</id>
    <title>fkie_cve-2026-40467</title>
    <updated>2026-10-02T10:42:22.779564+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40467"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wj49-xjpv-3f4m</id>
    <title>GHSA-wj49-xjpv-3f4m</title>
    <updated>2026-10-02T10:42:22.779586+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wj49-xjpv-3f4m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-40467</id>
    <title>msrc_CVE-2026-40467 — Use after free in gawk</title>
    <updated>2026-10-02T10:42:22.779601+00:00</updated>
    <content>msrc_CVE-2026-40467</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-40467"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3160</id>
    <title>OESA-2026-3160 — gawk security update</title>
    <updated>2026-10-02T10:42:22.779616+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: gawk</p>
<p>The gawk package is the GNU implementation of awk. The awk utility interprets a special-purpose programming language that makes it possible to handle simple data-reformatting jobs with just a few lines of code.

Security Fix(es):</p>
<p>Use After Free vulnerability has been found in &amp;quot;io.c&amp;quot; program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.(CVE-2026-40467)</p>
<p>Integer overflow vulnerability has been found in &amp;quot;builtin.c&amp;quot; program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.(CVE-2026-40468)</p>
<p>Integer overflow vulnerability has been found in &amp;quot;builtin.c&amp;quot; program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.(CVE-2026-40469)</p>
<p>Buffer overflow vulnerability has been found in &amp;quot;extension/readdir.c&amp;quot; program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.(CVE-2026-40553)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3160"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:40041</id>
    <title>RHSA-2026:40041 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-02T10:42:22.779648+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c gawk: gawk: Memory corruption via integer overflow gawk: gawk: Denial of Service due to integer overflow gawk: Gawk: Buffer overflow in ftype() routine may lead to code execution or denial of service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:40041"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:73429</id>
    <title>RLSA-2026:73429 — Moderate: gawk security update</title>
    <updated>2026-10-02T10:42:22.779669+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: gawk</p>
<p>The gawk packages contain the GNU version of awk, a text processing utility. Awk interprets a special-purpose programming language to do quick and easy text pattern matching and reformatting jobs.</p>
<p>Security Fix(es):</p>
<p>* gawk: gawk: Memory corruption via integer overflow (CVE-2026-40468)</p>
<p>* gawk: Gawk: Buffer overflow in ftype() routine may lead to code execution or denial of service (CVE-2026-40553)</p>
<p>* gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c (CVE-2026-40467)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:73429"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40467</id>
    <title>UBUNTU-CVE-2026-40467</title>
    <updated>2026-10-02T10:42:22.779692+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: gawk, Ubuntu:Pro:16.04:LTS: gawk, Ubuntu:Pro:18.04:LTS: gawk, Ubuntu:Pro:20.04:LTS: gawk, Ubuntu:22.04:LTS: gawk, Ubuntu:24.04:LTS: gawk, Ubuntu:26.04:LTS: gawk</p>
<p>Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40467"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3649</id>
    <title>WID-SEC-W-2026-3649 — Red Hat Enterprise Linux (gawk): Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:42:22.779718+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen, Speicherbeschädigungen zu verursachen und möglicherweise beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3649"/>
  </entry>
</feed>
