What is CVE-2026-6390?
CVE-2026-6390 is a format string vulnerability in GNU nano's multi-buffer error message handling. A specially crafted filename with printf format specifiers can lead to potential arbitrary code execution when opening multiple files. Users should update to a patched version of GNU nano.
Azərbaycanca: CVE-2026-6390 GNU nano mətn redaktorunda aşkar edilmiş format sətri zəifliyidir. İstifadəçi eyni anda bir neçə faylı açdıqda xüsusi hazırlanmış fayl adındakı printf format spesifikatorları vasitəsilə ixtiyari kod icrasına səbəb ola bilər. GNU nano-nun təsirlənmiş versiyalarını dərhal yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: GNU
FAQ2
Which functionality of GNU nano is affected by CVE-2026-6390?
The vulnerability affects the multi-buffer error message handling in GNU nano.
What does an attacker need to do to exploit CVE-2026-6390?
The attacker needs to craft a filename with printf format specifiers that is triggered when opening multiple files simultaneously.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.