VORANT. Threat Intelligence Sign in Get the full feed

GNU patch fixes two DoS vulnerabilities

low vulnerability technology

CERT Polska coordinated disclosure of two GNU patch vulnerabilities that let malicious diff files crash or hang the utility.

CERT Polska disclosed two vulnerabilities in GNU patch, a widely used utility for applying diff files, reported by AFINE Team researchers Michał Majchrowicz and Marcin Wyczechowski. CVE-2026-56288 is a NULL pointer dereference caused by improper handling of consecutive end-of-file newline markers, which corrupts internal hunk data structures and leads to a crash when a NULL pointer is passed to fwrite(). CVE-2026-56289 is a denial-of-service issue stemming from improper validation of hunk line offsets, allowing a crafted patch file to specify an extremely large line number and force the application into an effectively infinite loop, consuming excessive CPU and hanging the process.

Both issues require a victim to process a specially crafted unified-diff patch file, making exploitation dependent on social engineering or automated patch-processing pipelines that ingest untrusted diffs. Both vulnerabilities are fixed upstream via dedicated commits. No evidence of active exploitation is mentioned; this is a coordinated disclosure of denial-of-service bugs rather than remote code execution.

Mentioned in this report

Vulnerabilities CVE-2026-56288CVE-2026-56289

Source reporting: https://cert.pl/en/posts/2026/07/CVE-2026-56288

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free