REDHAT-BUG-2458767: Medium severity GNU Nano vulnerability
A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2458767?
The severity of REDHAT-BUG-2458767 is medium, rated at 4.
How do I fix REDHAT-BUG-2458767?
To fix REDHAT-BUG-2458767, update GNU Nano to the latest patched version that addresses the format string vulnerability.
What is the risk associated with REDHAT-BUG-2458767?
The risk associated with REDHAT-BUG-2458767 is rated at 19, indicating a moderate potential impact on system security.
What type of vulnerability is REDHAT-BUG-2458767?
REDHAT-BUG-2458767 is a format string vulnerability that affects GNU Nano's multi-buffer error message handling.
When was REDHAT-BUG-2458767 published?
REDHAT-BUG-2458767 was published on April 15, 2026.