CVE Explorer
CVE-2026-56289
GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position.
This results in excessive CPU consumption and prevents the process from completing.
An attacker can trigger this behavior by supplying a malicious p
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"patch","repo":"https://cgit.git.savannah.gnu.org/cgit/patch.git/","vendor":"GNU","versions":[{"lessThanOrEqual":"2.8.0","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2e0cb3faa68b0a1d14aef7549461448edd5befab044bdb79b99a2d60e4eb2aae · sha256:52453c2350393877… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":4.6,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2e0cb3faa68b0a1d14aef7549461448edd5befab044bdb79b99a2d60e4eb2aae · sha256:52453c2350393877… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-835","description":"CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2e0cb3faa68b0a1d14aef7549461448edd5befab044bdb79b99a2d60e4eb2aae · sha256:52453c2350393877… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"tags":["third-party-advisory"],"url":"https://cert.pl/en/posts/2026/07/CVE-2026-56288"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2e0cb3faa68b0a1d14aef7549461448edd5befab044bdb79b99a2d60e4eb2aae · sha256:52453c2350393877… · /containers/cna/references/0
{"tags":["product"],"url":"https://cgit.git.savannah.gnu.org/cgit/patch.git/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2e0cb3faa68b0a1d14aef7549461448edd5befab044bdb79b99a2d60e4eb2aae · sha256:52453c2350393877… · /containers/cna/references/1
{"tags":["patch"],"url":"https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=faba04ef4f2b410257f76c1b9dc85e350929c4b9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2e0cb3faa68b0a1d14aef7549461448edd5befab044bdb79b99a2d60e4eb2aae · sha256:52453c2350393877… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.