CVE-2026-6843: Nano: nano: format string vulnerability leads to denial of service

Published Apr 21, 2026
·
Updated

A flaw was found in nano. A local user could exploit a format string vulnerability in the statusline() function. By creating a directory with a name containing printf specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This results in a Denial of Service (DoS) for the nano application.

Other sources

Format string vulnerability in nano's statusline(). Directory names containing printf specifiers (%s) are stored in errormessage and later passed as format string to statusline() with no args. Causes stack reads and SEGV.

Verified on nano 8.7 with ASAN. BZ#2455127. Reported by Michał Majchrowicz and Marcin Wyczechowski, AFINE Team.

Red Hat

Nano: nano: format string vulnerability leads to denial of service

Microsoft

Affected Software

11 affected componentsFixes available
GNU Nano=8.7
Microsoft azl3 nano 6.4-2
GNU Nano=8.7
redhat OpenShift Container Platform=4.0
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux=10.0
Microsoft azl3 nano 6.4-3
debian/nano<=5.4-2+deb11u3, <=7.2-1+deb12u1
8.4-1+deb13u19.0-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/nano to a version that resolves this vulnerability.

    Fixed in 8.4-1+deb13u1Fixed in 9.0-1

Event History

Apr 21, 2026
Data Sourced
via Red Hat·08:47 AM
DescriptionSeverityAffected Software
Apr 22, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
May 3, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity
Updated
via Microsoft·08:02 AM
Affected Software
Jun 5, 2026
Data Sourced
via Launchpad·07:54 PM
Description
Data Sourced
via Debian·07:54 PM
DescriptionAffected Software
Jun 7, 2026
Data Sourced
via Ubuntu·07:53 PM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-6843?

CVE-2026-6843 has been assessed as a medium severity vulnerability due to its potential to cause a denial of service.

2

How do I fix CVE-2026-6843?

To mitigate CVE-2026-6843, users should upgrade to a patched version of GNU nano that addresses the format string vulnerability.

3

Who is affected by CVE-2026-6843?

CVE-2026-6843 affects local users of GNU nano version 8.7 or earlier who can create directories with names containing printf specifiers.

4

What causes CVE-2026-6843?

CVE-2026-6843 is caused by a format string vulnerability in the statusline() function of GNU nano.

5

What is the potential impact of CVE-2026-6843?

The potential impact of CVE-2026-6843 is denial of service, which can disrupt the normal operation of the application.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203