Skip to main content

Threats Tagged 'cve-2026-56289'

View all threats tagged with 'cve-2026-56289'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-56289

Threats Tagged 'cve-2026-56289'

Click on any threat for detailed analysis and mitigation recommendations

0

This security update addresses two vulnerabilities in the patch utility. CVE-2026-56288 involves a crafted unified-diff patch file that can cause a null pointer dereference. CVE-2026-56289 involves improper validation of hunk line offsets that can lead to denial of service. The vulnerabilities affect multiple specific versions of the patch utility, including various SUSE and Ubuntu package versions. The severity is assessed as low.

Join the discussion
0

Two vulnerabilities in GNU patch utility were addressed in a security update. CVE-2026-56288 involves a crafted unified-diff patch file causing a NULL pointer dereference, leading to a denial of service (DoS) via a crash. CVE-2026-56289 concerns improper validation of hunk line offsets that can also cause a denial of service. The issues affect certain versions of the patch utility distributed by Red Hat and SUSE. A security update is available that fixes these vulnerabilities.

Join the discussion

A security update has been released for Red Hat Hardened Images RPMs addressing CVE-2026-56289. This update includes patched versions of the 'patch' RPM for aarch64 and x86_64 architectures. The vulnerability is classified with medium severity and relates to a specific security flaw identified by Red Hat Product Security.

Join the discussion

GNU patch contains a denial of service (DoS) vulnerability caused by improper validation of hunk line offsets in unified-diff input. A malicious patch file can specify an extremely large line number, causing the utility to enter an effectively infinite processing loop and consume excessive CPU resources. This results in the process becoming unresponsive and requiring manual termination. The issue has been fixed in a specific commit.

Join the discussion

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cve-2026-56289
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses