FYI, CVE-2026-56392 and CVE-2026-56391 were assigned to GNU patch. Debian correctly marked them as having no security impact [1] [2].
It is annoying that Afine feels that wasting free software maintainers time is good advertising for their business [3]. I appreciate the bug reports, but certainly someone with the ability to invoke 'patch' correctly knows not to use it on untrusted files and how to kill it if it has run for longer than a few seconds... Collin [1] https://security-tracker.debian.org/tracker/CVE-2026-56288 [2] https://security-tracker.debian.org/tracker/CVE-2026-56289 [3] https://afine.com/
