Impact
A Use-After-Free flaw was identified in the do_getline_redir() routine of gawk’s io.c file. The vulnerability can cause the program to terminate unexpectedly, resulting in a denial-of-service condition. This weakness is classified as CWE-416.
Affected Systems
GNU gawk versions 5.4.0 and earlier are affected. No specific fixed release is listed in the CVE data; users must seek an updated release or apply the official patch.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score of < 1% reflects a very low but non-zero likelihood, and it is not listed in CISA’s KEV catalog. It can be triggered by feeding specially crafted input to gawk; the attack vector is inferred to be local or remote through processed data, but it does not provide remote code execution.
OpenCVE Enrichment
Ubuntu USN