VDB

JLSEC-2026-13

JLSEC-2026-13 PUBLISHED CVSS 9.300000190734863 CRITICAL

`do_ed_script` in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter.

Risk Scores

CVSS 2.0
9.300000190734863

Affected Products

VendorProductVersions
Juliapatch_jll0
Juliapatch_jll0, 0

Timeline

  • Mar 31, 2026 CVE Published
  • Jul 25, 2026 CVE Updated
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›