Executive brief
A memory management flaw has been identified in gawk, a widely used tool for processing text and data on Unix-like systems. This vulnerability can cause the program to crash when processing specific input commands. While primarily impacting system stability, such crashes can disrupt automated data processing tasks and scripts.
Technical details
A Use After Free (UAF) vulnerability exists in the 'do_getline_redir()' routine within 'io.c' of GNU gawk. The root cause is the premature dereferencing of the 'redir_exp' pointer before its final use in redirection logic. An attacker who can provide a crafted AWK script or input that triggers specific redirection error paths can cause the application to reference freed memory, leading to a denial-of-service (crash). The issue is local in nature, requiring the ability to execute gawk with controlled parameters or scripts. This vulnerability was fixed in gawk version 5.4.1 by moving the DEREF calls to the appropriate exit points of the routine.
Affected products
- GNU gawk All versions through 5.4.0
Timeline
- 2026-04-03: patched: Fix committed to gawk repository by Arnold Robbins.
- 2026-07-13: disclosed: Vulnerability disclosed by CERT Polska.
- 2026-07-13: advisory: CVE-2026-40467 published.