CVE-2018-6952: Double Free
A double free exists in the anotherhunk function in pch.c in GNU patch through 2.7.6.
Other sources
GNU patch through version 2.7.6 is vulnerable to a double freeing of memory when supplied a crafted patch file leading to a crash.
Upstream Issue:
https://savannah.gnu.org/bugs/index.php?53133
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6952?
CVE-2018-6952 is classified as a high severity vulnerability due to the potential for crash and denial of service.
How do I fix CVE-2018-6952?
To fix CVE-2018-6952, upgrade GNU patch to version 2.7.7 or later.
What exploitation methods are associated with CVE-2018-6952?
Exploitation of CVE-2018-6952 involves supplying a crafted patch file that triggers the double free condition.
What are the implications of CVE-2018-6952 on system stability?
CVE-2018-6952 can lead to unpredictable application behavior, including crashes, impacting overall system stability.
Which versions of GNU patch are affected by CVE-2018-6952?
All versions of GNU patch up to and including 2.7.6 are affected by CVE-2018-6952.