CVE-2026-6843Disclosure(gnu / enterprise_linux)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gnu enterprise_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This results in a Denial of Service (DoS) for the `nano` application.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-134

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • nano
  • openshift_container_platform

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-22); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
enterprise_linuxnanoopenshift_container_platform

7 versions affected across 3 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-22: 3Mentions · 2026-06-03: 1Patch / Workaround · 2026-06-03: 1Technical Details · 2026-04-22: 3Technical Details · 2026-06-03: 104-2206-03
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-223
Disclosure3
2026-06-031
Patch1
Full discourse4 posts
  • WindowsForum@windowsforum
    Patch

    🪟 GNU nano format-string crash (CVE-2026-6843) = your terminal isn’t as “safe” as it looks. Even “medium” DoS bugs can kneecap CI/WSL/containers fast. Patch. https://windowsforum.com/threads/cve-2026-6843-gnu-nano-format-string-dos-and-why-windows-shops-should-patch.422091/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #SecurityUpdates #WslAndContainers #Cve20266843 #GnuNano https://t.co/CROugTroSh

    Post summary

    The post highlights a medium DoS format‑string vulnerability in GNU nano (CVE‑2026‑6843) affecting Windows terminals and advises applying the available patch.

    0000046
    1.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6843 A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `print… https://www.cve.org/CVERecord?id=CVE-2026-6843 ----- Traducción: CVE-2026-6843 Se … http://infoflow.cloud`

    Post summary

    The post announces a newly discovered format‑string vulnerability in nano that can be triggered by local users via specially named directories; no PoC, exploit, patch, or active misuse is reported.

    0000037
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6843 A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `print… https://www.cve.org/CVERecord?id=CVE-2026-6843

    Post summary

    Nano’s statusline function has a disclosed format string flaw; no PoC, patch, or active exploitation reported yet.

    00000190
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6843 Format String Vulnerability in Nano Statusline Function Leading to Denial of Service https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6843

    Post summary

    An advisory on CVE-2026-6843, highlighting a format string vulnerability in the Nano Statusline function that can lead to denial of service.

    0000042
    4.0K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appgnunano8.7--
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
Appredhatopenshift_container_platform4.0--

Explore more