Sceawere
Vulnerability Detail
CVE-2026-102474UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dash printf Heap Buffer Overflow
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4
- Creation Date
- 15h ago
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 6
- Attack Type
- Out-of-bounds Write
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \u or \U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past that reservation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.0",
"pubDate": "2026-09-29T10:17:10.707Z",
"pubdate": "2026-09-29T10:17:10.707Z",
"executiveSummary": "A heap-based buffer overflow vulnerability exists within the dash shell's printf builtin functionality. The flaw originates from an incorrect memory reservation size when processing Unicode escape sequences (\\u and \\U).\nSpecifically, the application allocates a fixed buffer of four bytes to accommodate the conversion of these escape sequences. However, certain multi-byte Unicode characters can expand to five or six bytes during conversion, leading to an out-of-bounds write of one or two bytes beyond the allocated memory segment.\nThis vulnerability affects dash and impacts both printf and echo %b builtins. An attacker capable of supplying controlled input—such as through dash -c or positional arguments—can trigger the overflow.\nThe risk implication includes potential memory corruption, which may lead to application crashes or, theoretically, arbitrary code execution depending on the heap layout and the attacker's ability to manipulate adjacent memory structures.\nThe vulnerability requires local access to invoke the shell with malicious parameters. There is no requirement for remote network interaction, making this a local privilege escalation or denial-of-service vector for environments where dash is used as an interpreter for untrusted user inputs.",
"technicalDetails": "The root cause of this vulnerability is an integer size mismatch and insufficient memory allocation logic within the dash printf builtin implementation. When dash processes escape sequences, specifically those represented as \\u (16-bit Unicode) or \\U (32-bit Unicode), it attempts to translate these sequences into their multi-byte UTF-8 representations for output.\nThe internal logic reserves a static buffer size of four bytes to store the resulting character. While four bytes are sufficient for many standard Unicode characters, valid UTF-8 sequences can reach up to six bytes in length. When the conversion process encounters a character requiring five or six bytes, the implementation fails to reallocate or bounds-check the output buffer, resulting in an out-of-bounds write.\nThe attack flow begins when a user invokes the dash shell and passes a crafted string containing specific Unicode escape sequences to either the printf utility or the echo utility with the %b format specifier. Because these builtins are handled within the dash process, the overflow occurs in the context of the shell process memory space.\nExploitation involves the following steps: First, the attacker identifies a mechanism to supply arbitrary arguments to dash, such as via script execution, command substitution, or direct command line interface usage. Second, the attacker embeds a Unicode sequence that resolves to a 5- or 6-byte UTF-8 sequence. Third, upon execution, the dash printf logic attempts to write the converted sequence into the insufficient 4-byte buffer. The resulting overflow allows the attacker to overwrite adjacent data on the heap.\nThe impact of this write-past-boundary depends on what data resides adjacent to the printf buffer in the heap. In a typical exploitation scenario, this could be used to corrupt function pointers, object metadata, or other critical variables, potentially diverting control flow or inducing a crash (Denial of Service). As dash is often used as /bin/sh on many POSIX-compliant systems, this vulnerability potentially affects a wide array of system scripts and background tasks that process untrusted input.\nThere are no specific authentication requirements beyond local shell access. The privilege level required is equal to the level at which the dash instance is running, meaning that if a privileged script (e.g., a setuid or root-cron job) utilizes dash and accepts user-supplied input to printf or echo %b, this vulnerability could facilitate privilege escalation."
}