Bug 2510722 (CVE-2026-69152)

Summary: CVE-2026-69152 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aadhikar, aazores, abarbaro, abrianik, abuckta, akostadi, alizardo, amasferr, anjoseph, anpicker, anthomas, anujha, aruklets, aschwart, asoldano, aszczucz, ataylor, bbaranow, bbrownin, bmaxwell, boliveir, brasmith, bsmejkal, bstansbe, cdrage, chfoley, cmah, cochase, dbosanac, dbruscin, dfreiber, dkeler, dkuc, dlofthou, dmayorov, doconnor, dranck, drichtar, drow, dschmidt, dymurray, eaguilar, ebaron, ehelms, ehugonne, ewittman, fmariani, ggainey, ggrzybek, gmalinko, gparvin, gtanzill, hasun, ibolton, istudens, ivassile, iweiss, jachapma, janstey, jburrell, jbuscemi, jchui, jfula, jhe, jlanda, jlledo, jmatsuok, jmatthew, jmontleo, jowilson, jpasqual, jprabhak, jraez, jreimann, jtolenti, juwatts, jwon, kaycoth, kshier, ktsao, kvanderr, lchilton, mcarlett, mdellweg, mdessi, mhulan, mosmerov, mposolda, mreynolds, mrizzi, mstipich, msvehla, nboldt, nipatil, nmoumoul, nwallace, nyancey, oaljalju, ometelka, orabin, osousa, pantinor, parichar, pberan, pcattana, pcreech, pesilva, pgaikwad, pjindal, pmackay, progier, psrna, ptisnovs, rchan, rexwhite, rgodfrey, rhaigner, rhel-process-autobot, rjohnson, rkubis, rmartinc, rstancel, rstepani, rushinde, sdawley, sfeifer, simaishi, slucidi, smallamp, snegrini, spichugi, sseago, ssilvert, stcannon, sthirugn, sthorger, suppawar, swoodman, syedriko, tasato, tbordaz, tcunning, teagle, thason, thjenkin, tmalecek, tsedmik, vashirov, vdosoudi, vkumar, vmuzikar, watson-tool-maintainers, wtam, xdharmai, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the brace-expansion library. The `expand()` function does not apply `maxLength` when constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop, resulting in a denial of service. This issue is due to an incomplete mitigation of CVE-2026-14257.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2511786, 2511788, 2511790, 2511792, 2511793, 2511794, 2511795, 2511796, 2511798, 2511800, 2511801, 2511802, 2511803, 2511804, 2511807, 2511808, 2511809, 2511810, 2511812, 2511818, 2511822, 2511825, 2511826, 2511785, 2511787, 2511789, 2511791, 2511797, 2511799, 2511805, 2511806, 2511811, 2511814, 2511816, 2511820, 2511824    
Bug Blocks:    

Description OSIDB Bzimport 2026-08-03 18:01:36 UTC
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

Comment 3 errata-xmlrpc 2026-08-10 13:15:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:52841 https://access.redhat.com/errata/RHSA-2026:52841

Comment 4 errata-xmlrpc 2026-08-12 14:17:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:54371 https://access.redhat.com/errata/RHSA-2026:54371

Comment 5 errata-xmlrpc 2026-08-13 11:34:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:54530 https://access.redhat.com/errata/RHSA-2026:54530

Comment 7 errata-xmlrpc 2026-08-17 09:49:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:55541 https://access.redhat.com/errata/RHSA-2026:55541

Comment 8 errata-xmlrpc 2026-08-17 11:59:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55601 https://access.redhat.com/errata/RHSA-2026:55601

Comment 9 errata-xmlrpc 2026-08-17 14:33:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55603 https://access.redhat.com/errata/RHSA-2026:55603

Comment 10 errata-xmlrpc 2026-08-20 16:07:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:57590 https://access.redhat.com/errata/RHSA-2026:57590

Comment 11 errata-xmlrpc 2026-08-24 06:57:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:58819 https://access.redhat.com/errata/RHSA-2026:58819