← Vulnerability feed

Vulnerability record · CVE-2026-56288 · published 9 July 2026

CVE-2026-56288: Gnu patch null pointer dereference vulnerability

Gnu · Patch

GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing. An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service. This issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313

4.6 CVSS 4.0 Medium EPSS 0.17% · top 94.6% CWE-476 · NULL pointer dereference
4.6CVSS 4.0 base score
0.17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
13 Jul 2026Last modified by NVD

Description

GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing. An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service. This issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-56288 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2018-20969Gnu patch os command injection vulnerabilitydo_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-1…EPSS 2.7%7.8CVE-2019-13638Gnu patch os command injection vulnerabilityGNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style d…EPSS 4.5%7.8CVE-2018-1000156Gnu patch improper input validation vulnerabilityGNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed)…EPSS 5.3%7.5CVE-2015-1396Gnu patch path traversal vulnerabilityA Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a pa…EPSS 3.3%7.5CVE-2018-6951Gnu patch null pointer dereference vulnerabilityAn issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of…EPSS 8.4%7.5CVE-2018-6952Gnu patch double free vulnerabilityA double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.EPSS 8.2%7.5CVE-2015-1395Fedoraproject fedora path traversal vulnerabilityDirectory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary f…EPSS 11%5.9CVE-2019-13636Gnu patch link following vulnerabilityIn GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2026-56288), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.