CVE-2026-56289
Last modified
CVE-2026-56289 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Patch | <= 2.8.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-56289?
How severe is CVE-2026-56289?
How do I fix CVE-2026-56289?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-56283Capgo before 12.128.2 contains an html injection vulnerabili…5.4
- CVE-2026-56284Capgo (Cap-go/capgo) before 12.128.2 contains an information…6.9
- CVE-2026-56285Nitter's /video media proxy endpoint fails to validate targe…8.6
- CVE-2026-56286Capgo before 12.128.2 contains an authentication bypass vuln…8.1
- CVE-2026-56287A boolean-based SQL Injection vulnerability exists in Apache…8.1
- CVE-2026-56288GNU patch is vulnerable to a NULL pointer dereference when p…5.5
- CVE-2026-5629A vulnerability was detected in Belkin F9K1015 1.00.10. The …8.8
- CVE-2026-56290Joomla Extension - joomlack.fr - Unauthenticated file upload…9.8
- CVE-2026-56291Joomla Extension - balbooa.com - Unauthenticated file upload…9.8
- CVE-2026-56292Joomla Extension - acymailing.com - SQL Injection in AcyMail…7.5
- CVE-2026-56293Capgo before 12.128.2 contains an authorization flaw in tran…5.4
- CVE-2026-56294capacitor-native-biometric before 12.128.2 contains an authe…4.8
Are you affected by CVE-2026-56289?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
