Dash: dash: super-polynomial backtracking in pmatch when libc fnmatch is disabled
Published Sep 29, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.13%
Description
A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU.
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 6
dash
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | dash | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Rebuild dash with --enable-fnmatch so pathname matching uses libc fnmatch. Until then, do not run dash globs, case, or ${var#pat} / ${var%pat} against attacker-controlled names with multi-star patterns. There is no upstream backtracking bound in the internal matcher.
Red Hat statement
Red Hat rates this vulnerability as having a Moderate impact because exploitation requires local access and can only result in a denial of service through excessive CPU resource consumption, without compromising system confidentiality or integrity. Furthermore, standard builds on Red Hat Enterprise Linux utilize glibc pattern matching facilities rather than the standalone fallback implementation, significantly limiting exposure under default configurations. Exploitation is constrained to non-standard environments where internal pattern expansion is active and untrusted users are permitted to provide wildcard expressions or crafted directory structures.
Red Hat mitigation
Rebuild dash with --enable-fnmatch so pathname matching uses libc fnmatch. Until then, do not run dash globs, case, or ${var#pat} / ${var%pat} against attacker-controlled names with multi-star patterns. There is no upstream backtracking bound in the internal matcher.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 30, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.13% (0.00130) | 2.24th | v5 (v2026.06.15) |
| Oct 1, 2026 | 0.13% (0.00130) | 2.22th | v5 (v2026.06.15) |
References (4)
- https://access.redhat.com/security/cve/CVE-2026-102473 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2543005 issue-trackingx_refsource_REDHATIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-102473
- https://www.cve.org/CVERecord?id=CVE-2026-102473
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-102473 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2543005 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-102473 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-102473 |
Change history (0)
No recorded changes yet.