[Git][security-tracker-team/security-tracker][master] Add new gawk issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 13 22:13:56 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9fb5a2d3 by Salvatore Bonaccorso at 2026-07-13T23:13:26+02:00
Add new gawk issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -403,13 +403,17 @@ CVE-2026-49876 (Authenticated SSRF in Gravitino JobManager allows server-side HT
 CVE-2026-41041 (URL path injection via unencoded user-supplied identifiers vulnerabili ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-40553 (Buffer overflow vulnerability has been found in "extension/readdir.c"  ...)
-	TODO: check
+	- gawk <unfixed>
+	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843
 CVE-2026-40469 (Integer overflow vulnerability has been found in "builtin.c" program f ...)
-	TODO: check
+	- gawk <unfixed>
+	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=ae1b2d508f46913269a9e62aceda3636afe8147b
 CVE-2026-40468 (Integer overflow vulnerability has been found in "builtin.c" program f ...)
-	TODO: check
+	- gawk <unfixed>
+	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7
 CVE-2026-40467 (Use After Free vulnerability has been found in "io.c" program file of  ...)
-	TODO: check
+	- gawk <unfixed>
+	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8
 CVE-2026-26396 (OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in th ...)
 	TODO: check
 CVE-2026-22103 (The NPC start endpoint on the web server at port 8090 is vulnerable to ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9fb5a2d35ddb23695d0494485c56da6a0d95f05b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9fb5a2d35ddb23695d0494485c56da6a0d95f05b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260713/a56585ed/attachment.htm>


More information about the debian-security-tracker-commits mailing list