From 73ed7ce85cc78effb94daf028c9af6b4e5252e50 Mon Sep 17 00:00:00 2001
From: Collin Funk <collin.funk1@gmail.com>
Date: Mon, 20 Apr 2026 23:43:51 -0700
Subject: [PATCH] diff3: check for integer overflows when reading line numbers
 from diff
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

Reported by Michał Majchrowicz.
* NEWS: Mention the bug fix.
* src/diff3.c (readnum): Return nullptr if the line number would
overflow.

CVE: CVE-2026-53910
Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50]
Signed-off-by: Peter Marko <peter.marko@siemens.com>
---
 NEWS        | 8 ++++++++
 THANKS      | 1 +
 src/diff3.c | 3 ++-
 3 files changed, 11 insertions(+), 1 deletion(-)

diff --git a/NEWS b/NEWS
index a8115f7..bfe20d4 100644
--- a/NEWS
+++ b/NEWS
@@ -1,5 +1,13 @@
 GNU diffutils NEWS                                    -*- outline -*-
 
+ * Noteworthy changes in release ?.? (????-??-??) [?]
+
+** Bug fixes
+
+  diff3 no longer overflows integers when reading line numbers from the
+  diff program.
+  [bug present since "the beginning"]
+
 * Noteworthy changes in release 3.12 (2025-04-08) [stable]
 
 ** Bug fixes
diff --git a/THANKS b/THANKS
index a96b68d..a372954 100644
--- a/THANKS
+++ b/THANKS
@@ -13,6 +13,7 @@ Chris Hanson <cph@gnu.org>
 Jim Kingdon  <kingdon@panix.com>
 Tom Lord  <lord@gnu.org>
 David J. MacKenzie  <djm@gnu.org>
+Michał Majchrowicz  <mmajchrowicz@afine.com>
 Roland McGrath  <roland@redhat.com>
 Jim Meyering  <jim@meyering.net>
 Gene Myers  <gene@eecs.berkeley.edu>
diff --git a/src/diff3.c b/src/diff3.c
index 1dfba37..1a74407 100644
--- a/src/diff3.c
+++ b/src/diff3.c
@@ -1020,7 +1020,8 @@ readnum (char *s, lin *pnum)
 
   do
     {
-      num = c - '0' + num * 10;
+      if (ckd_mul (&num, num, 10) || ckd_add (&num, num, c - '0'))
+        return nullptr;
       c = *++s;
     }
   while (c_isdigit (c));
