CVE-2026-102474

Description

A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \u or \U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past that reservation.

Statement

This vulnerability is rated as Moderate severity because exploitation requires local access and the ability to pass crafted Unicode escape sequences directly into the shell's built-in formatting utilities. In Red Hat Enterprise Linux, dash is not deployed as the default system shell (/bin/sh is linked to bash), restricting exposure primarily to environments where dash is deliberately installed and executed on untrusted input. Consequently, the flaw presents a limited blast radius consisting of out-of-bounds heap memory corruption without direct privilege escalation under standard operating conditions.

Mitigation

No practical runtime mitigation is available in the shipped build. Do not pass untrusted data into dash printf/echo %b or into dash -c as a positional argument. The fix is to raise the CHECKSTRSPACE reservation at both printf call sites to 8. The later unaligned-access memcpy change in conv_escape does not enlarge that reservation and does not fix this issue.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score4N/A4
Attack VectorLocalN/ALocal
Attack ComplexityLowN/ALow
Privileges RequiredNoneN/ANone
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityNoneN/ANone
Integrity ImpactLowN/ALow
Availability ImpactNoneN/ANone

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

cve.org: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Understanding the Weakness (CWE)

Integrity

Technical Impact: Modify Memory; Execute Unauthorized Code or Commands

Write operations could cause memory corruption. In some cases, an adversary can modify control data such as return addresses in order to execute unexpected code.

Availability

Technical Impact: DoS: Crash, Exit, or Restart

Attempting to access out-of-range, invalid, or unauthorized memory could cause the product to crash.

Other

Technical Impact: Unexpected State

Subsequent write operations can produce undefined or unexpected results.

Acknowledgements

Red Hat would like to thank Shubham Raj (Causal Security) for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.