Executive brief
The diff3 tool, part of the GNU diffutils suite used for comparing and merging files, contains a flaw in how it calculates line positions. If an attacker can provide a specially crafted file or control the output of the underlying comparison program, they could cause the tool to crash or potentially execute unauthorized code. This could impact developers or automated systems that rely on diff3 for merging code or processing data from untrusted sources.
Technical details
A heap-based buffer overflow exists in the diff3 tool of GNU diffutils due to multiple signed integer overflows within line-mapping calculations in src/diff3.c. Specifically, incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds. An attacker can exploit this by controlling the output of the diff program used by diff3 (for example, via the --diff-program argument pointing to a malicious script). This leads to insufficient memory allocation and subsequent out-of-bounds writes. The vulnerability is addressed by limiting line numbers to LIN_MAX / 2 in the readnum function to prevent overflow during subsequent arithmetic operations.
Affected products
- GNU diffutils All through 3.12
Timeline
- 2026-04-21: patched: Fix committed to upstream repository.
- 2026-07-22: disclosed: Vulnerability disclosed by CERT Polska.
- 2026-07-22: advisory: NVD record published.
References
- https://cert.pl/en/posts/2026/07/CVE-2026-53910
- https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50
- https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815
- https://git.savannah.gnu.org/cgit/diffutils.git/