The vendor explicitly identifies these products as affected by this CVE.
- nano.src as a component of Red Hat Enterprise Linux 10
- nano.src as a component of Red Hat Enterprise Linux 6
- nano.src as a component of Red Hat Enterprise Linux 7
- nano as a component of Red Hat Enterprise Linux 8
- nano.src as a component of Red Hat Enterprise Linux 8
- nano as a component of Red Hat Enterprise Linux 9
- nano.src as a component of Red Hat Enterprise Linux 9
- openshift/ose-rhel-coreos-8 as a component of Red Hat OpenShift Container Platform 4
- openshift/ose-rhel-coreos-9 as a component of Red Hat OpenShift Container Platform 4
- Summary
- A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This results in a Denial of Service (DoS) for the `nano` application.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
