CVE-2026-6390

Publication date 23 July 2026

Last updated 7 August 2026


Ubuntu priority

Cvss 3 Severity Score

6.8 · Medium

Score breakdown

Description

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.

Status

Package Ubuntu Release Status
nano 26.04 LTS resolute
Vulnerable, fix deferred
24.04 LTS noble
Vulnerable, fix deferred
22.04 LTS jammy
Vulnerable, fix deferred
20.04 LTS focal
Vulnerable, fix deferred
18.04 LTS bionic
Vulnerable, fix deferred
16.04 LTS xenial
Vulnerable, fix deferred
14.04 LTS trusty
Vulnerable, fix deferred

Severity score breakdown

CVSS version: CVSS v3.0

Base score 6.8 · Medium

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H


Access our resources on patching vulnerabilities