Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6843

22
FAUCET Score

CVE-2026-6843 is a format string vulnerability affecting the nano text editor, specifically in the statusline() function. An attacker can exploit this flaw by creating a directory with a name containing printf format specifiers, which causes nano to crash when attempting to display the directory name. The vulnerability results in a denial of service condition affecting the application. The vulnerability has a CVSS v3.1 score of 5.5 (MEDIUM severity) with a local attack vector requiring no privileges but user interaction. While the attack complexity is low, the impact is limited to availability—there is no impact to confidentiality or integrity. The EPSS score of 0.00013 indicates minimal real-world exploitation probability relative to other CVEs. There is no evidence of active exploitation at this time. The vulnerability is not tracked in CISA's Known Exploited Vulnerabilities catalog, and it remains inactive on threat intelligence hot lists. Community attention appears limited, suggesting this is a lower-priority issue suitable for standard patching cycles rather than emergency remediation.

Impacted Technologies

VendorProductVersion(s)CPE
8.7CPE matchmatch criteria
cpe:2.3:a:gnu:nano:8.7:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.11%
Probability of exploitation in next 30 days
EPSS Percentile
1.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0011 is in the 1st percentile among its peer group of 5,758 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

microsoftpatch availablevia msrc
Product: azl3 nano 6.4-3 on Azure Linux 3.0Fixed in: 6.4-3
microsoftpatch availablevia msrc
Product: azl3 nano 6.4-2 on Azure Linux 3.0Fixed in: 6.4-3
microsoftpatch availablevia msrc
Product: 21416-17084Fixed in: 6.4-3
microsoftpatch availablevia msrc
Product: 17720-17084Fixed in: 6.4-3

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-6843Moderate

Nano: nano: format string vulnerability leads to denial of service

Apr 14, 2026

References

access.redhat.com / security/cve/CVE-2026-6843
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory