← Vulnerability feed

Vulnerability record · CVE-2018-6952 · published 13 February 2018

CVE-2018-6952: Gnu patch double free vulnerability

Gnu · Patch

A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.

7.5 CVSS 3.0 High EPSS 8.2% · top 5.3% CWE-415 · Double free
7.5CVSS 3.0 base score, v2 5.0
8.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-6952 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2018-20969Gnu patch os command injection vulnerabilitydo_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-1…EPSS 2.7%7.8CVE-2019-13638Gnu patch os command injection vulnerabilityGNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style d…EPSS 4.5%7.8CVE-2018-1000156Gnu patch improper input validation vulnerabilityGNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed)…EPSS 5.3%7.5CVE-2015-1396Gnu patch path traversal vulnerabilityA Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a pa…EPSS 3.3%7.5CVE-2018-6951Gnu patch null pointer dereference vulnerabilityAn issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of…EPSS 8.4%7.5CVE-2015-1395Fedoraproject fedora path traversal vulnerabilityDirectory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary f…EPSS 11%5.9CVE-2019-13636Gnu patch link following vulnerabilityIn GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.EPSS 3.9%5.5CVE-2021-45261Gnu patch vulnerabilityAn Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.EPSS 0.71%

Source: NIST National Vulnerability Database (record CVE-2018-6952), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.