VDB
JLSEC-2026-12
JLSEC-2026-12
PUBLISHED
CVSS 9.300000190734863 CRITICAL
GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via the patch utility. This is similar to FreeBSD's CVE-2015-1418 however although they share a common ancestry the code bases have diverged over time.
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Julia | patch_jll | 0, 0 |
Timeline
- Mar 31, 2026 CVE Published
- Mar 31, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
References
- http://packetstormsecurity.com/files/154124/GNU-patch-Command-Injection-Directory-Traversal.html url
- http://rachelbythebay.com/w/2018/04/05/bangpatch/ url
- https://access.redhat.com/errata/RHSA-2018:1199 url
- https://access.redhat.com/errata/RHSA-2018:1200 url
- https://access.redhat.com/errata/RHSA-2018:2091 url
- https://access.redhat.com/errata/RHSA-2018:2092 url
- https://access.redhat.com/errata/RHSA-2018:2093 url
- https://access.redhat.com/errata/RHSA-2018:2094 url
- https://access.redhat.com/errata/RHSA-2018:2095 url
- https://access.redhat.com/errata/RHSA-2018:2096 url
- https://access.redhat.com/errata/RHSA-2018:2097 url
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=894667#19 url
- https://lists.debian.org/debian-lts-announce/2018/04/msg00013.html url
- https://savannah.gnu.org/bugs/index.php?53566 url
- https://seclists.org/bugtraq/2019/Aug/29 url
- https://seclists.org/bugtraq/2019/Jul/54 url
- https://security.gentoo.org/glsa/201904-17 url
- https://usn.ubuntu.com/3624-1/ url
- https://usn.ubuntu.com/3624-2/ url
- https://web.archive.org/web/20180405231329/https://twitter.com/kurtseifried/status/982028968877436928 url
…and 1 more