Executive brief
A vulnerability has been identified in the nano text editor, a common tool used for editing files on Linux systems. An attacker can crash the application by tricking a user into opening or interacting with a directory that has a specially crafted name containing specific characters. This results in a denial of service, preventing the user from using the editor to modify files.
Technical details
A format string vulnerability exists in the `statusline()` function of the nano text editor. The issue occurs when directory names containing `printf` specifiers (such as `%s`) are stored in the `errormessage` variable and subsequently passed as a format string to `statusline()` without accompanying arguments. This leads to out-of-bounds stack reads and a segmentation fault (SEGV). An attacker can exploit this by creating a directory with a malicious name and inducing the application to display that name in the status bar. The vulnerability has been verified on nano version 8.7.
Affected products
- GNU nano 8.7
- Red Hat Enterprise Linux 6.0, 7.0, 8.0, 9.0, 10.0
- Red Hat OpenShift Container Platform 4.0
Timeline
- 2026-04-21: disclosed: Reported by AFINE Team via Red Hat Bugzilla
- 2026-04-22: advisory: Initial NVD publication