Heap-Based Buffer Overflow in GNU Diffutils diff3 Tool
CVE-2026-53910
2.1LOW
What is CVE-2026-53910?
The diff3 tool within the GNU diffutils package is exposed to a heap-based buffer overflow due to multiple signed integer overflows occurring during line-mapping calculations. This vulnerability arises when processed with crafted diff outputs, potentially leading to insufficient memory allocation and subsequent out-of-bounds writes. An attacker can exploit this by controlling the diff output, allowing for crashes and could lead to remote code execution under certain circumstances. The issue was addressed in the commit identified by 9ff04d5b84743e331e80b589335a52c5480d1815.
Affected Version(s)
diffutils 0 <= 3.12
References
CVSS V4
Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michał Majchrowicz (AFINE Team)
Marcin Wyczechowski (AFINE Team)