Sceawere
Vulnerability Detail
CVE-2026-102473UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dash Recursive Pattern Matching Denial-of-Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 15h ago
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 6
- Attack Type
- Inefficient Regular Expression Complexity
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-29T10:17:10.383Z",
"pubdate": "2026-09-29T10:17:10.383Z",
"executiveSummary": "This vulnerability involves a Denial-of-Service (DoS) condition within the dash shell's internal pattern matching implementation. When dash is compiled without libc fnmatch support, the fallback pmatch() function exhibits inefficient algorithmic complexity when processing specific wildcard patterns. By supplying crafted strings containing multiple asterisk (*) wildcards, a local attacker can trigger unbounded recursion during the pattern matching process. This leads to excessive CPU consumption, effectively freezing the shell process or the parent service relying on dash for glob expansion. The vulnerability is present in environments where dash is configured without external system library dependencies for pattern matching. Because this is a local exploitation vector, the attacker must have the ability to influence filenames or input passed to the matcher. The primary risk is resource exhaustion, which can impact system availability if dash is used in critical automated scripts or services that process untrusted user-supplied input.\nThis flaw specifically affects the internal pmatch() routine. Exploitation does not require elevated privileges; any local user capable of generating file structures or triggering shell globbing can execute the attack. There is no network exposure component inherent to the vulnerability, as it is strictly limited to the local execution environment.",
"technicalDetails": "The vulnerability resides within the pmatch() function in dash, which serves as an internal implementation of glob pattern matching when the build configuration omits usage of the system's libc fnmatch. The root cause is a catastrophic backtracking scenario triggered by the recursive handling of the asterisk (*) wildcard character. In standard glob implementations, an asterisk matches any sequence of characters; however, the internal pmatch() implementation fails to account for the exponential complexity growth associated with multiple nested or sequential wildcards.\nWhen a user provides a pattern containing numerous asterisks, such as '*.*.*.*.*.tar.gz', the pmatch() algorithm attempts to branch into every possible permutation of character matching for each star segment. Because the function uses unbounded recursion to explore these potential matches, the computational cost grows exponentially relative to the number of wildcards provided and the length of the candidate filename. This behavior is reminiscent of ReDoS (Regular Expression Denial of Service) but operates at the shell globbing level.\nThe attack flow proceeds as follows: First, the attacker identifies an entry point where input is processed by the dash globber. This could involve creating specific directory structures containing files that match the malicious pattern, or passing input directly to a script that utilizes dash's built-in expansion logic. Second, the attacker triggers the glob match against the crafted pattern. Third, the pmatch() function enters the recursive routine, consuming CPU cycles as it attempts to resolve the ambiguous matches. Fourth, the shell process becomes unresponsive or enters a 'busy' state, effectively stalling any dependent processes or system management tasks. \nThe absence of a memoization layer or a depth-limiting mechanism in pmatch() means that once the recursion begins, it must exhaust its search space before returning, or until the process is terminated by external signals such as a watchdog timer or manual administrator intervention. The memory footprint remains relatively low, but the CPU-bound nature of the recursion makes this an effective local DoS vector against any automation relying on dash. The exploitation does not require special authentication beyond the ability to perform shell operations or create filesystem objects that are subsequently processed by a dash-based glob operation.\nThe vulnerability is fundamentally a failure to implement proper algorithmic bounds on pattern matching logic, favoring simplicity in the fallback implementation over resilience against maliciously crafted input."
}