CVE-2026-40468
Critical · CVSS 9.1gawk — Integer overflow leading to heap metadata overwrite / memory exhaustion
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-190
Description
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
Search profile — drives PoC discovery
Symbols builtin.c062f2f2581b991362c046f7f2e238ffa34e6f8c7
Keywords CVE-2026-40468gawkinteger overflowbuiltin.cheap overflowCWE-190gawk 5.4.0memory exhaustionheap metadata overwrite
Versions: ≤ 5.4.0
References
Status: enriched · ingested 2026-07-14T06:00:21.000Z · profiled 2026-07-14T06:30:21.000Z