Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-13636

22
FAUCET Score

CVE-2019-13636 describes a symlink following vulnerability in GNU patch versions through 2.7.6, specifically affecting inp.c and util.c. This medium-severity vulnerability (CVSS 5.9) has a network attack vector and high integrity impact, allowing an attacker to potentially modify files via mishandled symlinks. There is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting a low current threat landscape.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.7.6CPE matchmatch criteria
cpe:2.3:a:gnu:patch:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

5.9MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
3.90%
Probability of exploitation in next 30 days
EPSS Percentile
89.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0389 is in the 85th percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (33)

microsoftpatch availablevia msrc
Product: patch-2.7.6-9.azl3.aarch64.rpm on Azure Linux 3.0 ARMFixed in: 2.7.6-9
microsoftpatch availablevia msrc
Product: 16926-16823Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 16927-16817Fixed in: 2.7.6-9
microsoftpatch availablevia msrc
Product: 16927-17084Fixed in: 2.7.6-9
microsoftpatch availablevia msrc
Product: patch-2.7.6-9.azl3.x86_64.rpm on Azure Linux 3.0 x64Fixed in: 2.7.6-9
microsoftpatch availablevia msrc
Product: 16925-16820Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: cm1 patch 2.7.6-7 on CBL Mariner 1.0Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: cbl2 patch 2.7.6-7 on CBL Mariner 2.0Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: azl3 patch 2.7.6-9 on Azure Linux 3.0Fixed in: 2.7.6-9
microsoftpatch availablevia msrc
Product: 13120-12137Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13121-12137Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13122-12138Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13123-12138Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13124-12139Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13125-12139Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13126-12140Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13127-12140Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: 13128-12356Fixed in: 2.7.6-9
microsoftpatch availablevia msrc
Product: 13129-12357Fixed in: 2.7.6-9
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-2.7.6-7.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-debuginfo-2.7.6-7.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-2.7.6-7.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-debuginfo-2.7.6-7.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-2.7.6-7.cm2.x86_64.rpm on CBL Mariner 2.0 x64Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-debuginfo-2.7.6-7.cm2.x86_64.rpm on CBL Mariner 2.0 x64Fixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-2.7.6-7.cm2.aarch64.rpm on CBL Mariner 2.0 ARMFixed in: 2.7.6-7
microsoftpatch availablevia msrc
Product: patch-debuginfo-2.7.6-7.cm2.aarch64.rpm on CBL Mariner 2.0 ARMFixed in: 2.7.6-7
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: patch-0:2.7.6-11.el8
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: patch

Vendor Advisories (4)

microsoft2024-Jun/CVE-2019-13636

CVE-2019-13636

Jun 11, 2024
microsoft2020-Aug/CVE-2019-13636

CVE-2019-13636

Aug 11, 2020
redhatCVE-2019-13636Moderate

patch: the following of symlinks in inp.c and util.c is mishandled in cases other than input files

Jul 24, 2019
microsoft2019-Jul/CVE-2019-13636Moderate

In GNU patch through 2.7.6 the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.

Jul 9, 2019

References

packetstormsecurity.com / files/154124/GNU-patch-Command-Injection-Directory-Traversal.html
github.com / irsl/gnu-patch-vulnerabilities
git.savannah.gnu.org / cgit/patch.git/commit
Mailing ListPatchVendor Advisory
lists.debian.org / debian-lts-announce/2019/07/msg00016.html
Third Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/SVWWGISFWACROJJPVJJL4UBLVZ7LPOLT
seclists.org / bugtraq/2019/Aug/29
seclists.org / bugtraq/2019/Jul/54
security.gentoo.org / glsa/201908-22
security.netapp.com / advisory/ntap-20190828-0001
usn.ubuntu.com / 4071-1
usn.ubuntu.com / 4071-2
debian.org / security/2019/dsa-4489