CVE-2023-4156 is a heap out-of-bounds read vulnerability in the gawk package's builtin.c, affecting various versions of Fedora and Red Hat Enterprise Linux. This flaw, with a CVSS score of 7.1 (High), can be triggered locally with low attack complexity, potentially leading to system crashes or the disclosure of sensitive information. While the vulnerability is rated as high severity, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding it. The low EPSS score further suggests a low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE match | cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:* | ||
< 5.1.1CPE matchmatch criteria | cpe:2.3:a:gnu:gawk:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.