Your message dated Fri, 24 Jul 2026 13:06:16 +0200 with message-id <amNHKFl3SYeahQv5@nuc> has caused the report #1142675, regarding diffutils: CVE-2026-53910 to be marked as having been forwarded to the upstream software author(s) [email protected]
(NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) -- 1142675: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142675 Debian Bug Tracking System Contact [email protected] with problems
--- Begin Message ---Hello. I received this from the Debian BTS. (Thank you, Salvatore) The report says this is fixed in [9ff04d5], but it also mentions [73ed7ce], and when I do "git log" in my clone I also find additional security-related commits in addition to those two. So: How many commits should I really apply from the git repo to fix CVE-2026-53910 ? Also, while we are at it: Can I expect a diffutils 3.13 release soon? Thanks. ----- Forwarded message from Salvatore Bonaccorso <[email protected]> ----- Date: Fri, 24 Jul 2026 08:10:04 +0200 From: Salvatore Bonaccorso <[email protected]> To: Debian Bug Tracking System <[email protected]> Subject: Bug#1142675: diffutils: CVE-2026-53910 Resent-CC: [email protected], [email protected], [email protected] X-Mailer: reportbug 13.2.0+nmu1 Source: diffutils Version: 1:3.12-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Hi, The following vulnerability was published for diffutils. CVE-2026-53910[0]: | diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer | overflow due to multiple signed integer overflows in line‑mapping | calculations. Incorrect arithmetic in mapping line ranges can result | in corrupted values being used for memory allocation and loop | bounds. When processing crafted diff output, these overflows may | cause the application to allocate insufficient memory and | subsequently perform out‑of‑bounds writes during internal | processing. An attacker who can control the output of the diff | program used by diff3 (e.g. via --diff-program pointing to a | malicious script) can trigger out-of-bounds writes, resulting in a | crash and potentially remote code execution depending on the | environment. This issue has been fixed in commit | 9ff04d5b84743e331e80b589335a52c5480d1815 If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-53910 https://www.cve.org/CVERecord?id=CVE-2026-53910 [1] https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50 [2] https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815 Please adjust the affected versions in the BTS as needed. Regards, Salvatore ----- End forwarded message -----
--- End Message ---

