ALAS2023-2026-2035


Amazon Linux 2023 Security Advisory: ALAS2023-2026-2035
Advisory Released Date: 2026-08-04
Advisory Updated Date: 2026-08-04
Severity: Important

Issue Overview:

Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below. (CVE-2026-40467)

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below. (CVE-2026-40468)

Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below. (CVE-2026-40553)


Affected Packages:

gawk


Issue Correction:
Run dnf update gawk --releasever 2023.12.20260803 or dnf update --advisory ALAS2023-2026-2035 --releasever 2023.12.20260803 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    gawk-all-langpacks-5.1.0-3.amzn2023.0.4.aarch64
    gawk-devel-5.1.0-3.amzn2023.0.4.aarch64
    gawk-debugsource-5.1.0-3.amzn2023.0.4.aarch64
    gawk-debuginfo-5.1.0-3.amzn2023.0.4.aarch64
    gawk-5.1.0-3.amzn2023.0.4.aarch64

noarch:
    gawk-doc-5.1.0-3.amzn2023.0.4.noarch

src:
    gawk-5.1.0-3.amzn2023.0.4.src

x86_64:
    gawk-all-langpacks-5.1.0-3.amzn2023.0.4.x86_64
    gawk-devel-5.1.0-3.amzn2023.0.4.x86_64
    gawk-debugsource-5.1.0-3.amzn2023.0.4.x86_64
    gawk-debuginfo-5.1.0-3.amzn2023.0.4.x86_64
    gawk-5.1.0-3.amzn2023.0.4.x86_64