Medium severity5.5NVD Advisory· Published Jul 9, 2026· Updated Jul 13, 2026
CVE-2026-56288
CVE-2026-56288
Description
GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing. An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service.
This issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313
Affected products
4- osv-coords2 versionspkg:rpm/opensuse/patch&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/patch&distro=openSUSE%20Tumbleweed
< 2.7.6-160000.4.1+ 1 more
- (no CPE)range: < 2.7.6-160000.4.1
- (no CPE)range: < 2.8-3.1
Patches
Vulnerability mechanics
References
2- cgit.git.savannah.gnu.org/cgit/patch.git/commit/nvdPatch
- cert.pl/en/posts/2026/07/CVE-2026-56288nvdThird Party Advisory
News mentions
1- GNU Patch & Wget: Six Vulnerabilities Including Heap Overflows and DoS Disclosed TogetherVypr Intelligence · Jul 10, 2026