Description
diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds.
When processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out‑of‑bounds writes during internal processing. 
An attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment.


This issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815 

NOTE:
The project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges.
Published: 2026-07-22
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a heap‑based buffer overflow in the diff3 tool of GNU diffutils, caused by multiple signed integer overflows in line‑mapping calculations. When crafted diff output or a malicious script is supplied via the --diff-program option, Diff3 performs erroneous arithmetic that results in insufficient memory allocation and subsequent out‑of‑bounds writes. This can cause the program to crash and, in certain environments, may lead to remote code execution. The weakness is a classic signed integer overflow, CWE‑190.

Affected Systems

All versions of GNU diffutils that include the diff3 utility prior to the fix in commit 9ff04d5b84743e331e80b589335a52c5480d1815 are affected. The issue applies to the default diff3 binary supplied with the diffutils package on Linux and other Unix‑like systems.

Risk and Exploitability

The CVSS score of 2.1 indicates a low overall severity, and the EPSS score of < 1% indicates a very low probability of exploitation, suggesting limited publicly known exploitation activity. However, because the overflow is triggered by controlled diff output or a user‑supplied diff program, the attack vector is inferred to be input‑based or a form of command‑injection. Any system that invokes diff3 on untrusted input and allows a malicious --diff-program could, in principle, be compromised, giving attackers the potential to execute arbitrary code depending on the execution environment. Since the vulnerability is not listed in the CISA KEV catalog, it is not known to have active exploit campaigns at this time.

Generated by OpenCVE AI on August 2, 2026 at 17:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update GNU diffutils to a version that contains commit 9ff04d5b84743e331e80b589335a52c5480d1815.
  • If an update is not immediately possible, configure diff3 to use the built‑in diff program by removing any --diff-program option or resetting the environment variable that supplies it, thereby preventing malicious scripts from being invoked.
  • Restrict the files and execution permissions of any user‑provided diff program scripts and audit systems for unexpected modifications to the diffutils binaries.

Generated by OpenCVE AI on August 2, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

threat_severity

Low


Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds. When processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out‑of‑bounds writes during internal processing.  An attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment. This issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815 diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds. When processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out‑of‑bounds writes during internal processing.  An attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment. This issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815  NOTE: The project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges.

Thu, 23 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Gnu
Gnu diffutils
Vendors & Products Gnu
Gnu diffutils

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds. When processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out‑of‑bounds writes during internal processing.  An attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment. This issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815
Title Heap-based Buffer Overflow in GNU diffutils
Weaknesses CWE-190
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-07-27T10:58:52.287Z

Reserved: 2026-06-11T07:44:52.179Z

Link: CVE-2026-53910

cve-icon Vulnrichment

Updated: 2026-07-22T19:11:27.490Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-22T14:17:21.030

Modified: 2026-07-27T12:16:45.250

Link: CVE-2026-53910

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-22T13:42:50Z

Links: CVE-2026-53910 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T18:00:05Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound