---
title: "CVE-2026-40468\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-40468?format=md
keywords: index, follow
---

# CVE-2026-40468

Publication date 13 July 2026

Last updated 6 August 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**9.1 · Critical**

[Score breakdown](https://ubuntu.com/security/CVE-2026-40468?format=md#impact-score)

Toggle side navigation

## Description

Integer overflow vulnerability has been found in "builtin.c" program file
of gawk. This issue may lead to memory exhaustion on the hosting operating
system and could be used to overwrite gawk heap metadata and objects with
attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| gawk | 26.04 LTS resolute | Fixed 1:5.3.2-1ubuntu1.1 |
| 24.04 LTS noble | Fixed 1:5.2.1-2ubuntu0.1 |
| 22.04 LTS jammy | Fixed 1:5.1.0-1ubuntu0.2 |
| 20.04 LTS focal | Fixed 1:5.0.1+dfsg-1ubuntu0.1+esm1  Ubuntu Pro |
| 18.04 LTS bionic | Fixed 1:4.1.4+dfsg-1ubuntu0.1~esm2  Ubuntu Pro |
| 16.04 LTS xenial | Fixed 1:4.1.3+dfsg-0.1ubuntu0.1~esm2  Ubuntu Pro |
| 14.04 LTS trusty | Fixed 1:4.0.1+dfsg-2.1ubuntu2+esm2  Ubuntu Pro |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Severity score breakdown

CVSS version:

CVSS v4.0

[CVSS v4.0](https://ubuntu.com/security/CVE-2026-40468?format=md)
[CVSS v3.0](https://ubuntu.com/security/CVE-2026-40468?format=md)

**Base score**

2.1 · Low

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Attack requirements | Present |
  | Privileges required | None |
  | User interaction | None |
  | Vulnerable system - Confidentiality impact | None |
  | Vulnerable system - Integrity impact | Low |
  | Vulnerable system - Availability impact | Low |
  | Subsequent system - Confidentiality impact | None |
  | Subsequent system - Integrity impact | None |
  | Subsequent system - Availability impact | Low |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 2.1 · Low |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40468)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-40468)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-40468)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-40468)

### Related Ubuntu Security Notices (USN)

+ [USN-8588-1](https://usn.ubuntu.com/USN-8588-1)
+ Gawk vulnerabilities
+ 22 July 2026

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-40468>
