CVE-2026-14650

Description

A flaw was found in Grass. A local attacker could exploit a vulnerability in the UTF-8 Character Handler, specifically within the grass_compiler::raw_to_parse_error function, by executing a manipulation. This could lead to a denial of service, making the system or application unavailable to legitimate users.

Statement

This flaw has a Low impact, as it requires a local authenticated attacker to trigger a denial of service within the Grass UTF-8 Character Handler. The vulnerability's nature, affecting a compiler during local execution, limits its broader risk in typical Red Hat environments where such tools are not exposed to untrusted input in production.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other); Reduce Performance

This issue can make the product perform more slowly. If an attacker can influence the number of iterations in the loop, then this performance problem might allow a denial of service by consuming more platform resources than intended.

Frequently Asked Questions

Want to get errata notifications? Sign up here.