High severity7.5NVD Advisory· Published Jul 13, 2026· Updated Jul 14, 2026
CVE-2026-40553
CVE-2026-40553
Description
Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below.
Affected products
4Patches
Vulnerability mechanics
References
2- cgit.git.savannah.gnu.org/cgit/gawk.git/commit/nvdPatch
- cert.pl/en/posts/2026/07/CVE-2026-40467nvdThird Party Advisory
News mentions
1- Patch Tuesday - July 2026Rapid7 Blog · Jul 14, 2026