CVE Tools

CVE-2018-1000156

Published: Apr 6, 2018Updated: Apr 14, 2025 Sources: CVE List NVD BDUCWE-20

Description

GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via the patch utility. This is similar to FreeBSD's CVE-2015-1418 however although they share a common ancestry the code bases have diverged over time.

In plain language

AI Worth attention

If your system runs GNU Patch 2.7.6, a malicious patch file could make the patch tool run code—this is mainly a risk for people who apply untrusted patch files.

Executive summary

CVE-2018-1000156 is a local code execution issue in GNU Patch 2.7.6 where processing a crafted patch file can trigger unsafe invocation of the internal `ed` editor with unsanitized input.

If affected, business impact
Malicious code on serverSystem takeover riskData theft riskService disruption

What to do now

  1. Check which version of the patch program you have installed (look for GNU Patch and whether it is 2.7.6).
  2. If you are on GNU Patch 2.7.6, upgrade to a version newer than 2.7.6 from your distro’s updates.
  3. Stop applying patch files from email, the internet, or unknown sources; only apply patches from trusted repositories or vendors.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:LAC:LPR:NUI:RS:UC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 11 more affected products View all →

Exploitability

1 exploit source identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Initial Access
View detailed technique mapping

References

and 28 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2018-1000156 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows