CVE-2026-6390

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-23 05:16

Updated : 2026-09-01 13:19


NVD link : CVE-2026-6390

Mitre link : CVE-2026-6390

CVE.ORG link : CVE-2026-6390


JSON object : View

Products Affected

No product.

CWE
CWE-134

Use of Externally-Controlled Format String