CVE-2018-6951: Null Pointer Dereference
Published Feb 13, 2018
·Updated
An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuitdifftype function in pch.c, aka a "mangled rename" issue.
Affected Software
5 affected components
GNU patch<=2.7.6
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
debian/patch<=2.7.6-7, <=2.8-2
Event History
Feb 13, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:09 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·04:05 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:06 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6951?
CVE-2018-6951 has a severity rating that indicates it can cause a denial of service due to a segmentation fault.
2
How do I fix CVE-2018-6951?
To fix CVE-2018-6951, upgrade GNU patch to version 2.7.7 or later.
3
What is the impact of CVE-2018-6951?
The impact of CVE-2018-6951 is a denial of service caused by a NULL pointer dereference.
4
Which versions of GNU patch are affected by CVE-2018-6951?
GNU patch versions up to and including 2.7.6 are affected by CVE-2018-6951.
5
Is CVE-2018-6951 present in Ubuntu Linux?
Yes, CVE-2018-6951 is present in specific versions of Ubuntu Linux that use the vulnerable GNU patch.