#1149887 dash: CVE-2026-102473

Package:
src:dash
Source:
src:dash
Submitter:
Salvatore Bonaccorso
Date:
2026-10-03 21:51:03 UTC
Severity:
normal
Tags:
#1149887#5
Date:
2026-10-03 21:48:42 UTC
From:
To:
Hi,

The following vulnerability was published for dash.

CVE-2026-102473[0]:
| A flaw was found in dash. When built without libc fnmatch, the
| internal pmatch() matcher implements * by unbounded recursion over
| candidate positions. A local user who can plant filenames, or
| otherwise feed that matcher, can make a short multi-star pattern
| such as *.*.*.*.*.tar.gz consume excessive CPU.

TTBOMK, and at time of writing this bugreport, only the Bugzilla entry
from Red Hat was available. Can you check?


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-102473
https://www.cve.org/CVERecord?id=CVE-2026-102473
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2543005

Regards,
Salvatore