CVE-2026-102473: Red Hat Enterprise Linux 6

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU.

Affected products

Published 2026-09-29. Last modified 2026-09-30.