Amazon Linux 2023 Security Advisory: ALAS2023-2026-2035
Advisory Released Date: 2026-08-04
Advisory Updated Date: 2026-08-04
FAQs regarding Amazon Linux ALAS/CVE Severity
Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below. (CVE-2026-40467)
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below. (CVE-2026-40468)
Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve code execution, although the latter has not been confirmed to be feasible. It affects gawk in versions 5.4.0 and below. (CVE-2026-40553)
Affected Packages:
gawk
Issue Correction:
Run dnf update gawk --releasever 2023.12.20260803 or dnf update --advisory ALAS2023-2026-2035 --releasever 2023.12.20260803 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
gawk-all-langpacks-5.1.0-3.amzn2023.0.4.aarch64
gawk-devel-5.1.0-3.amzn2023.0.4.aarch64
gawk-debugsource-5.1.0-3.amzn2023.0.4.aarch64
gawk-debuginfo-5.1.0-3.amzn2023.0.4.aarch64
gawk-5.1.0-3.amzn2023.0.4.aarch64
noarch:
gawk-doc-5.1.0-3.amzn2023.0.4.noarch
src:
gawk-5.1.0-3.amzn2023.0.4.src
x86_64:
gawk-all-langpacks-5.1.0-3.amzn2023.0.4.x86_64
gawk-devel-5.1.0-3.amzn2023.0.4.x86_64
gawk-debugsource-5.1.0-3.amzn2023.0.4.x86_64
gawk-debuginfo-5.1.0-3.amzn2023.0.4.x86_64
gawk-5.1.0-3.amzn2023.0.4.x86_64