CVE-2026-14650
Description
A flaw was found in Grass. A local attacker could exploit a vulnerability in the UTF-8 Character Handler, specifically within the grass_compiler::raw_to_parse_error function, by executing a manipulation. This could lead to a denial of service, making the system or application unavailable to legitimate users.
Statement
This flaw has a Low impact, as it requires a local authenticated attacker to trigger a denial of service within the Grass UTF-8 Character Handler. The vulnerability's nature, affecting a compiler during local execution, limits its broader risk in typical Red Hat environments where such tools are not exposed to untrusted input in production.
Mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other); Reduce Performance
This issue can make the product perform more slowly. If an attacker can influence the number of iterations in the loop, then this performance problem might allow a denial of service by consuming more platform resources than intended.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.