mirror of
https://git.yoctoproject.org/poky
synced 2026-09-20 21:49:33 +02:00
NVD [3] identifies upstream merge commit [2] as the fix. The CVE-specific change is its second parent [1], which adds 32-bit overflow checking in do_sub(). [1] https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=aa7272a6e1184cdd21ab8f89200219abd8053eda [2] https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=ae1b2d508f46913269a9e62aceda3636afe8147b [3] https://nvd.nist.gov/vuln/detail/CVE-2026-40469 (From OE-Core rev: 421a3d2166e922c5a8085be0aa9daab13920b613) Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com> Reviewed-by: Leonid Iziumtsev <leonid.iziumtsev@est.tech> Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Paul Barker <paul@pbarker.dev>