Hi Santiago, hi Collin, On Fri, Jul 24, 2026 at 07:17:40AM -0700, Collin Funk wrote: > Santiago Vila <[email protected]> writes: > > > Hello. > > > > I received this from the Debian BTS. (Thank you, Salvatore) > > > > The report says this is fixed in [9ff04d5], but it also mentions > > [73ed7ce], and when I do "git log" in my clone I also find additional > > security-related commits in addition to those two. > > > > So: How many commits should I really apply from the git repo to fix > > CVE-2026-53910 ? > > Do note that the CVE text is highly exaggerated, as many are: > > An attacker who can control the output of the diff program used by > diff3 (e.g. via --diff-program pointing to a malicious script) can > trigger out-of-bounds writes, resulting in a crash and potentially > remote code execution depending on the environment. > > If an "attacker" has access to write a malicious script on your local > environment and give them the ability to execute it, surely you have > larger problems than out-of-bounds writes in 'diff'...
Sorry indeed, I will mark the CVE as 'unimportant' with a negligible security impact in the security-tracker, Santiago feel free to downgrade the severity and then just mark it as fixed once you have a version which includes the fixes. No strict need to do an update in stable (or if you do then via a point release). Regards, Salvatore

