CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-40469

criticalCVSS 9.1covered by 3 sourcesfirst seen 2026-07-13
It was discovered that Gawk incorrectly handled memory when processing input using the getline redirection. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-40467) It was discovered that Gawk incorrectly handled certain integer calculations when allocating memory. An attacker could possibly use this issue to cause a denial of service or overwrite heap memory with attacker-controlled data. (CVE-2026-40468) It was discovered that Gawk incorrectly handled certain integer calculations when performing substitutions. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-40469) It was discovered that Gawk incorrectly handled memory when reading directory entries. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-40553)

CSIRTS triage

What
Gawk has vulnerabilities that could lead to denial of service or remote code execution due to improper memory handling and integer calculations.
Who is affected
Users of Gawk, particularly those on Ubuntu 26.04 LTS.
Urgency
Remediation is urgent as these vulnerabilities can be exploited to cause denial of service or execute arbitrary code.
Action
Update Gawk to the latest version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-40469

Get an email if CVE-2026-40469 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-40469

CVE.org record

Embed the live status

CVE-2026-40469 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-40469 status](https://www.csirts.com/badge/CVE-2026-40469)](https://www.csirts.com/cve/CVE-2026-40469)