Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-20969

26
FAUCET Score

CVE-2018-20969 describes a vulnerability in GNU patch through version 2.7.6, where the do_ed_script function in pch.c fails to properly block strings beginning with a '!' character, specifically within the context of 'ed' commands. This vulnerability carries a high CVSS score of 7.8, indicating that an attacker could achieve high confidentiality, integrity, and availability impacts with low attack complexity and user interaction. Despite its severity, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.7.6CPE matchmatch criteria
cpe:2.3:a:gnu:patch:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.8HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
2.68%
Probability of exploitation in next 30 days
EPSS Percentile
84.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0268 is in the 84th percentile among its peer group of 11,617 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (38)

microsoftpatch availablevia msrc
Product: patch-2.7.6-9.azl3.aarch64.rpm on Azure Linux 3.0 ARMFixed in: 2.7.6-9
microsoftpatch availablevia msrc
Product: 16925-16820Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 16926-16823Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 16927-17084Fixed in: 2.7.6-9
microsoftpatch availablevia msrc
Product: 13124-12139Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13125-12139Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13126-12140Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13127-12140Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-debuginfo-2.7.6-7.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-2.7.6-7.cm2.x86_64.rpm on CBL Mariner 2.0 x64Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-debuginfo-2.7.6-7.cm2.x86_64.rpm on CBL Mariner 2.0 x64Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-2.7.6-7.cm2.aarch64.rpm on CBL Mariner 2.0 ARMFixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-debuginfo-2.7.6-7.cm2.aarch64.rpm on CBL Mariner 2.0 ARMFixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-2.7.6-9.azl3.x86_64.rpm on Azure Linux 3.0 x64Fixed in: 2.7.6-9
microsoftpatch availablevia msrc
Product: 16927-16817Fixed in: 2.7.6-9
microsoftpatch availablevia msrc
Product: azl3 patch 2.7.6-9 on Azure Linux 3.0Fixed in: 2.7.6-9
microsoftpatch availablevia msrc
Product: cm1 patch 2.7.6-7 on CBL Mariner 1.0Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: cbl2 patch 2.7.6-7 on CBL Mariner 2.0Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13120-12137Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13121-12137Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13122-12138Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13123-12138Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13128-12356Fixed in: 2.7.6-9
microsoftpatch availablevia msrc
Product: 13129-12357Fixed in: 2.7.6-9
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-2.7.6-7.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-debuginfo-2.7.6-7.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-2.7.6-7.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 2.7.6-7
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: patch-0:2.7.1-12.el7_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Advanced Update SupportFixed in: patch-0:2.7.1-11.el7_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Telco Extended Update SupportFixed in: patch-0:2.7.1-11.el7_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsFixed in: patch-0:2.7.1-11.el7_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.5 Extended Update SupportFixed in: patch-0:2.7.1-11.el7_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Extended Update SupportFixed in: patch-0:2.7.1-11.el7_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: patch-0:2.7.6-9.el8_0
View patch

Vendor Advisories (4)

microsoft2024-Jun/CVE-2018-20969

CVE-2018-20969

Jun 11, 2024
microsoft2020-Aug/CVE-2018-20969

CVE-2018-20969

Aug 11, 2020
redhatCVE-2018-20969Important

patch: do_ed_script in pch.c does not block strings beginning with a ! character

Aug 16, 2019
microsoft2019-Aug/CVE-2018-20969Important

do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638 but the ! syntax is specific to ed and is unrelated to a shell metacharacter.

Aug 13, 2019

References

packetstormsecurity.com / files/154124/GNU-patch-Command-Injection-Directory-Traversal.html
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2019:2798
access.redhat.com / errata/RHSA-2019:2964
access.redhat.com / errata/RHSA-2019:3757
access.redhat.com / errata/RHSA-2019:3758
access.redhat.com / errata/RHSA-2019:4061
github.com / irsl/gnu-patch-vulnerabilities
git.savannah.gnu.org / cgit/patch.git/commit
PatchVendor Advisory
seclists.org / bugtraq/2019/Aug/29
ExploitMailing ListPatchThird Party Advisory