A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-23 05:16
Updated : 2026-09-01 13:19
NVD link : CVE-2026-6390
Mitre link : CVE-2026-6390
CVE.ORG link : CVE-2026-6390
JSON object : View
Products Affected
No product.
CWE
CWE-134
Use of Externally-Controlled Format String
