CVE-2015-1396: Debian Linux

High severity, CVSS 7.5. EPSS: 3.3% chance of exploitation in the next 30 days.

A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only; version 11.0 only
  • GNU Patch: before 2.7.4 (fixed in 2.7.4)

Published 2019-11-25. Last modified 2026-06-17.