Source: diffutils
Version: 1:3.12-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for diffutils.

CVE-2026-53910[0]:
| diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer
| overflow due to multiple signed integer overflows in line‑mapping
| calculations. Incorrect arithmetic in mapping line ranges can result
| in corrupted values being used for memory allocation and loop
| bounds. When processing crafted diff output, these overflows may
| cause the application to allocate insufficient memory and
| subsequently perform out‑of‑bounds writes during internal
| processing.  An attacker who can control the output of the diff
| program used by diff3 (e.g. via --diff-program pointing to a
| malicious script) can trigger out-of-bounds writes, resulting in a
| crash and potentially remote code execution depending on the
| environment.   This issue has been fixed in commit
| 9ff04d5b84743e331e80b589335a52c5480d1815


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-53910
    https://www.cve.org/CVERecord?id=CVE-2026-53910
[1] 
https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50
[2] 
https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to