It was discovered that Gawk incorrectly handled memory when processing input using the getline redirection. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-40467) It was discovered that Gawk incorrectly handled certain integer calculations when allocating memory. An attacker could possibly use this issue to cause a denial of service or overwrite heap memory with attacker-controlled data. (CVE-2026-40468) It was discovered that Gawk incorrectly handled certain integer calculations when performing substitutions. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-40469) It was discovered that Gawk incorrectly handled memory when reading directory entries. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-40553)
Multiple critical vulnerabilities have been identified in Gawk, including memory handling errors in `getline` redirection and integer calculation flaws during memory allocation and substitutions, which can lead to denial of service, heap memory corruption, or arbitrary code execution. The most severe issues, CVE-2026-40468 and CVE-2026-40469, carry a CVSS 3.1 score of 9.1 (CRITICAL). All vulnerabilities affect Gawk versions up to and including 5.4.0.