THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-6390 (MEDIUM 6.8) — A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow

[NVD] CVE-2026-6390 (MEDIUM 6.8) — A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow

lownvdPublished 2026-07-23

CVE-2026-6390 CVSS: 6.8 MEDIUM Published: 2026-07-23T05:16:38.360

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure,

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-6390