Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-53910: CWE-190 Integer Overflow or Wraparound in GNU diffutils

0
Low
VulnerabilityCVE-2026-53910cvecve-2026-53910cwe-190
Published: 07/22/2026 (07/22/2026, 13:42:50 UTC)
Source: CVE Database V5
Vendor/Project: GNU
Product: diffutils

Description

The diff3 tool from GNU diffutils contains a heap-based buffer overflow vulnerability caused by multiple signed integer overflows in line-mapping calculations. These overflows can lead to insufficient memory allocation and out-of-bounds writes when processing crafted diff output. An attacker able to control the diff program output used by diff3 may trigger these conditions, potentially causing a crash or remote code execution. The issue has been fixed in a specific commit, but no official patch or fixed version is explicitly stated in the provided data.

CVSS v4.0

Score 2.1low

Attack Vector
Local
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
Low
Vuln. Availability
Low
Subsq. Confidentiality
Low
Subsq. Integrity
Low
Subsq. Availability
Low
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/22/2026, 14:23:03 UTC

Technical Analysis

CVE-2026-53910 describes a vulnerability in the diff3 tool of GNU diffutils where multiple signed integer overflows occur during line-mapping calculations. This results in corrupted values used for memory allocation and loop bounds, causing heap-based buffer overflows. When diff3 processes specially crafted diff output—particularly if the diff program is controlled by an attacker via the --diff-program option—these overflows can lead to out-of-bounds writes. This may cause application crashes or potentially remote code execution depending on the environment. The vulnerability is tracked as CWE-190 (Integer Overflow or Wraparound) and has been addressed in commit 9ff04d5b84743e331e80b589335a52c5480d1815, though no official patch release details are provided.

Potential Impact

The vulnerability allows an attacker who can influence the diff output used by diff3 to cause heap-based buffer overflows. This can lead to application crashes and, depending on the environment, remote code execution. The CVSS 4.0 score is low (2.1), reflecting limited attack vector and complexity, but the impact includes potential privilege escalation or code execution if exploited.

Mitigation Recommendations

The issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815. However, no official patch or fixed version is explicitly stated in the provided data. Patch status is not yet confirmed—check the GNU diffutils vendor advisory or official repositories for current remediation guidance. Until a fixed version is applied, avoid using untrusted diff output with diff3, especially when using the --diff-program option to specify external diff programs.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
CERT-PL
Date Reserved
2026-06-11T07:44:52.179Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null

Threat ID: 6a60cec79c2644c7f828494d

Added to database: 07/22/2026, 14:08:07 UTC

Last enriched: 07/22/2026, 14:23:03 UTC

Last updated: 07/22/2026, 17:56:28 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses