Skip to main content

Threats Tagged 'cve-2026-56288'

View all threats tagged with 'cve-2026-56288'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-56288

Threats Tagged 'cve-2026-56288'

Click on any threat for detailed analysis and mitigation recommendations

0

This security update addresses two vulnerabilities in the patch utility. CVE-2026-56288 involves a crafted unified-diff patch file that can cause a null pointer dereference. CVE-2026-56289 involves improper validation of hunk line offsets that can lead to denial of service. The vulnerabilities affect multiple specific versions of the patch utility, including various SUSE and Ubuntu package versions. The severity is assessed as low.

Join the discussion
0

Two vulnerabilities in GNU patch utility were addressed in a security update. CVE-2026-56288 involves a crafted unified-diff patch file causing a NULL pointer dereference, leading to a denial of service (DoS) via a crash. CVE-2026-56289 concerns improper validation of hunk line offsets that can also cause a denial of service. The issues affect certain versions of the patch utility distributed by Red Hat and SUSE. A security update is available that fixes these vulnerabilities.

Join the discussion

GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing. An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service. This issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: cve-2026-56288
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses