VDB

JLSEC-2026-12

JLSEC-2026-12 PUBLISHED CVSS 6.800000190734863 MEDIUM

GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the `EDITOR_PROGRAM` invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via the patch utility. This is similar to FreeBSD's CVE-2015-1418 however although they share a common ancestry the code bases have diverged over time.

Risk Scores

CVSS 2.0
6.800000190734863

Affected Products

VendorProductVersions
Juliapatch_jll0, 0
Juliapatch_jll0

Timeline

  • Mar 31, 2026 CVE Published
  • Jul 25, 2026 CVE Updated
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›