Threats Tagged 'cve-2026-56288'
View all threats tagged with 'cve-2026-56288'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-56288'
Click on any threat for detailed analysis and mitigation recommendations
0 This security update addresses two vulnerabilities in the patch utility. CVE-2026-56288 involves a crafted unified-diff patch file that can cause a null pointer dereference. CVE-2026-56289 involves improper validation of hunk line offsets that can lead to denial of service. The vulnerabilities affect multiple specific versions of the patch utility, including various SUSE and Ubuntu package versions. The severity is assessed as low. Join the discussion | GCVE Database | 07/13/2026, 19:26:45 UTC Added: 07/16/2026, 10:37:40 UTC |
0 Two vulnerabilities in GNU patch utility were addressed in a security update. CVE-2026-56288 involves a crafted unified-diff patch file causing a NULL pointer dereference, leading to a denial of service (DoS) via a crash. CVE-2026-56289 concerns improper validation of hunk line offsets that can also cause a denial of service. The issues affect certain versions of the patch utility distributed by Red Hat and SUSE. A security update is available that fixes these vulnerabilities. Join the discussion | GCVE Database | 07/13/2026, 19:26:45 UTC Added: 07/11/2026, 09:38:29 UTC |
GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing. An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service. This issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313 Join the discussion | CVE Database V5 | 07/09/2026, 09:29:07 UTC Added: 07/09/2026, 10:35:43 UTC |
Showing 1 to 3 of 3 results