CVE-2018-6951: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 8.4% chance of exploitation in the next 30 days.

An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a "mangled rename" issue.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.10 only
  • GNU Patch: up to and including 2.7.6

Published 2018-02-13. Last modified 2026-06-17.