PT-2026-56776 · Gnu · Gnu Patch

·

CVE-2026-56289

·

Published

2026-07-09

·

Updated

2026-08-18

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU patch (affected versions not specified)
Description Improper validation of hunk line offsets in unified-diff input allows a denial of service (DoS). A hunk is a single block of changes within a diff file. By supplying a specially crafted patch file with an extremely large line number, an attacker can force the application into an effectively infinite processing loop while it attempts to locate the requested position. This leads to excessive CPU consumption, making the utility unresponsive and requiring manual termination.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92151
CVE-2026-56289
ECHO-6808-09A0-F94E
JLSEC-2026-1261
OESA-2026-3056
OPENSUSE-SU-2026:11260-1
OPENSUSE-SU-2026:21332-1
SUSE-SU-2026:22604-1
SUSE-SU-2026:22651-1
SUSE-SU-2026:22905-1
SUSE-SU-2026:23210-1
SUSE-SU-2026:2922-1
SUSE-SU-2026:3161-1

Affected Products

Gnu Patch