Your message dated Fri, 24 Jul 2026 13:06:16 +0200
with message-id <amNHKFl3SYeahQv5@nuc>
has caused the   report #1142675,
regarding diffutils: CVE-2026-53910
to be marked as having been forwarded to the upstream software
author(s) [email protected]

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142675: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142675
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Hello.

I received this from the Debian BTS. (Thank you, Salvatore)

The report says this is fixed in [9ff04d5], but it also mentions
[73ed7ce], and when I do "git log" in my clone I also find additional
security-related commits in addition to those two.

So: How many commits should I really apply from the git repo to fix
CVE-2026-53910 ?

Also, while we are at it: Can I expect a diffutils 3.13 release soon?

Thanks.

----- Forwarded message from Salvatore Bonaccorso <[email protected]> -----

Date: Fri, 24 Jul 2026 08:10:04 +0200
From: Salvatore Bonaccorso <[email protected]>
To: Debian Bug Tracking System <[email protected]>
Subject: Bug#1142675: diffutils: CVE-2026-53910
Resent-CC: [email protected], [email protected], [email protected]
X-Mailer: reportbug 13.2.0+nmu1

Source: diffutils
Version: 1:3.12-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for diffutils.

CVE-2026-53910[0]:
| diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer
| overflow due to multiple signed integer overflows in line‑mapping
| calculations. Incorrect arithmetic in mapping line ranges can result
| in corrupted values being used for memory allocation and loop
| bounds. When processing crafted diff output, these overflows may
| cause the application to allocate insufficient memory and
| subsequently perform out‑of‑bounds writes during internal
| processing.  An attacker who can control the output of the diff
| program used by diff3 (e.g. via --diff-program pointing to a
| malicious script) can trigger out-of-bounds writes, resulting in a
| crash and potentially remote code execution depending on the
| environment.   This issue has been fixed in commit
| 9ff04d5b84743e331e80b589335a52c5480d1815


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-53910
    https://www.cve.org/CVERecord?id=CVE-2026-53910
[1] 
https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50
[2] 
https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

----- End forwarded message -----

--- End Message ---

Reply via email to