← Vulnerability feed

Vulnerability record · CVE-2026-56289 · published 9 July 2026

CVE-2026-56289: Gnu patch vulnerability

Gnu · Patch

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9

4.6 CVSS 4.0 Medium EPSS 0.17% · top 94.6% CWE-835 · CWE-835
4.6CVSS 4.0 base score
0.17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
13 Jul 2026Last modified by NVD

Description

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-56289 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2018-20969Gnu patch os command injection vulnerabilitydo_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-1…EPSS 2.7%7.8CVE-2019-13638Gnu patch os command injection vulnerabilityGNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style d…EPSS 4.5%7.8CVE-2018-1000156Gnu patch improper input validation vulnerabilityGNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed)…EPSS 5.3%7.5CVE-2015-1396Gnu patch path traversal vulnerabilityA Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a pa…EPSS 3.3%7.5CVE-2018-6951Gnu patch null pointer dereference vulnerabilityAn issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of…EPSS 8.4%7.5CVE-2018-6952Gnu patch double free vulnerabilityA double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.EPSS 8.2%7.5CVE-2015-1395Fedoraproject fedora path traversal vulnerabilityDirectory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary f…EPSS 11%5.9CVE-2019-13636Gnu patch link following vulnerabilityIn GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2026-56289), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.