A heap out of bound read issue exists in builtin.c of gawk prior to version 5.1.1. The array "the_args" takes an unsafe index "val", while it does not validate the index to ensure the index refers to a valid position in the array (e.g., exceedingly large or negative). The vulnerability can cause crash of the software and might be used by attackers to read sensitive information. https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00000.html https://mail.gnu.org/archive/html/bug-gawk/2022-08/msg00023.html https://fossies.org/linux/gawk/ChangeLog#470 (Line: 470-475)
Created gawk tracking bugs for this issue: Affects: fedora-all [bug 2215940]