FYI, CVE-2026-56392 and CVE-2026-56391 were assigned to GNU patch.

Debian correctly marked them as having no security impact [1] [2].

It is annoying that Afine feels that wasting free software maintainers
time is good advertising for their business [3]. I appreciate the bug
reports, but certainly someone with the ability to invoke 'patch'
correctly knows not to use it on untrusted files and how to kill it if
it has run for longer than a few seconds...

Collin

[1] https://security-tracker.debian.org/tracker/CVE-2026-56288
[2] https://security-tracker.debian.org/tracker/CVE-2026-56289
[3] https://afine.com/

Reply via email to