Hi, The following vulnerability was published for dash. CVE-2026-102473[0]: | A flaw was found in dash. When built without libc fnmatch, the | internal pmatch() matcher implements * by unbounded recursion over | candidate positions. A local user who can plant filenames, or | otherwise feed that matcher, can make a short multi-star pattern | such as *.*.*.*.*.tar.gz consume excessive CPU. TTBOMK, and at time of writing this bugreport, only the Bugzilla entry from Red Hat was available. Can you check? If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-102473 https://www.cve.org/CVERecord?id=CVE-2026-102473 [1] https://bugzilla.redhat.com/show_bug.cgi?id=2543005 Regards, Salvatore