CVE-2026-56288: crafted unified-diff patch file can cause null pointer derefence (bsc#1271167).
CVE-2026-56289: improper validation of hunk line offsets can lead to denial of service (bsc#1271166).
Affected Packages
patch
SUSE Linux Enterprise Desktop 15 SP7SUSE Linux Enterprise High Performance Computing 15 SP7SUSE Linux Enterprise Module for Basesystem 15 SP7SUSE Linux Enterprise Server 15 SP7SUSE Linux Enterprise Server for SAP Applications 15 SP7