From 9ff04d5b84743e331e80b589335a52c5480d1815 Mon Sep 17 00:00:00 2001
From: Paul Eggert <eggert@cs.ucla.edu>
Date: Tue, 21 Apr 2026 00:30:50 -0700
Subject: [PATCH] diff3: prevent overflow in line offsets
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

Problem reported by Michał Majchrowicz.
* src/diff3.c (readnum): Limit line numbers to LIN_MAX / 2.

CVE: CVE-2026-53910
Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815]
Signed-off-by: Peter Marko <peter.marko@siemens.com>
---
 src/diff3.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/src/diff3.c b/src/diff3.c
index 4fed6a8..d32e6ad 100644
--- a/src/diff3.c
+++ b/src/diff3.c
@@ -1026,6 +1026,12 @@ readnum (char *s, lin *pnum)
     }
   while (c_isdigit (c));
 
+  /* Simplify overflow checking later, so that we can always add a
+     line number and a line count, or subtract two line numbers and
+     add 1 to the result, without worrying about overflow.  */
+  if (LIN_MAX / 2 < num)
+    return nullptr;
+
   *pnum = num;
   return s;
 }
