Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

ubuntu логотип

CVE-2026-56289

24 дня назад

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-56289

24 дня назад

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2026-56289

24 дня назад

Loop with Unreachable Exit Condition in GNU patch

EPSS: Низкий
debian логотип

CVE-2026-56289

24 дня назад

GNU patch is vulnerable to a denial of service (DoS) due to improper v ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3m3r-f94v-4mf8

24 дня назад

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9

CVSS3: 5.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21332-1

20 дней назад

Security update for patch

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3161-1

12 дней назад

Security update for patch

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2922-1

20 дней назад

Security update for patch

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-56289

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9

CVSS3: 5.5
0%
Низкий
24 дня назад
nvd логотип
CVE-2026-56289

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9

CVSS3: 5.5
0%
Низкий
24 дня назад
msrc логотип
CVE-2026-56289

Loop with Unreachable Exit Condition in GNU patch

0%
Низкий
24 дня назад
debian логотип
CVE-2026-56289

GNU patch is vulnerable to a denial of service (DoS) due to improper v ...

CVSS3: 5.5
0%
Низкий
24 дня назад
github логотип
GHSA-3m3r-f94v-4mf8

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9

CVSS3: 5.5
0%
Низкий
24 дня назад
suse-cvrf логотип
openSUSE-SU-2026:21332-1

Security update for patch

20 дней назад
suse-cvrf логотип
SUSE-SU-2026:3161-1

Security update for patch

12 дней назад
suse-cvrf логотип
SUSE-SU-2026:2922-1

Security update for patch

20 дней назад

Уязвимостей на страницу