Bug 2510722 (CVE-2026-69152) - CVE-2026-69152 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
Summary: CVE-2026-69152 brace-expansion: DoS via unbounded intermediate arrays, bypass...
Keywords:
Status: NEW
Alias: CVE-2026-69152
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2511786 2511788 2511790 2511792 2511793 2511794 2511795 2511796 2511798 2511800 2511801 2511802 2511803 2511804 2511807 2511808 2511809 2511810 2511812 2511818 2511822 2511825 2511826 2511785 2511787 2511789 2511791 2511797 2511799 2511805 2511806 2511811 2511814 2511816 2511820 2511824
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-03 18:01 UTC by OSIDB Bzimport
Modified: 2026-09-16 17:17 UTC (History)
188 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:52841 0 None None None 2026-08-10 13:16:07 UTC
Red Hat Product Errata RHSA-2026:54371 0 None None None 2026-08-12 14:17:21 UTC
Red Hat Product Errata RHSA-2026:54530 0 None None None 2026-08-13 11:34:51 UTC
Red Hat Product Errata RHSA-2026:55541 0 None None None 2026-08-17 09:49:51 UTC
Red Hat Product Errata RHSA-2026:55601 0 None None None 2026-08-17 11:59:10 UTC
Red Hat Product Errata RHSA-2026:55603 0 None None None 2026-08-17 14:33:56 UTC
Red Hat Product Errata RHSA-2026:57590 0 None None None 2026-08-20 16:08:03 UTC
Red Hat Product Errata RHSA-2026:58819 0 None None None 2026-08-24 06:57:17 UTC
Red Hat Product Errata RHSA-2026:61374 0 None None None 2026-08-31 10:01:32 UTC
Red Hat Product Errata RHSA-2026:62416 0 None None None 2026-09-02 07:31:50 UTC
Red Hat Product Errata RHSA-2026:64817 0 None None None 2026-09-08 04:06:33 UTC
Red Hat Product Errata RHSA-2026:68333 0 None None None 2026-09-16 17:17:53 UTC

Description OSIDB Bzimport 2026-08-03 18:01:36 UTC
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

Comment 3 errata-xmlrpc 2026-08-10 13:15:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:52841 https://access.redhat.com/errata/RHSA-2026:52841

Comment 4 errata-xmlrpc 2026-08-12 14:17:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:54371 https://access.redhat.com/errata/RHSA-2026:54371

Comment 5 errata-xmlrpc 2026-08-13 11:34:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:54530 https://access.redhat.com/errata/RHSA-2026:54530

Comment 7 errata-xmlrpc 2026-08-17 09:49:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:55541 https://access.redhat.com/errata/RHSA-2026:55541

Comment 8 errata-xmlrpc 2026-08-17 11:59:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55601 https://access.redhat.com/errata/RHSA-2026:55601

Comment 9 errata-xmlrpc 2026-08-17 14:33:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55603 https://access.redhat.com/errata/RHSA-2026:55603

Comment 10 errata-xmlrpc 2026-08-20 16:07:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:57590 https://access.redhat.com/errata/RHSA-2026:57590

Comment 11 errata-xmlrpc 2026-08-24 06:57:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:58819 https://access.redhat.com/errata/RHSA-2026:58819

Comment 14 errata-xmlrpc 2026-08-31 10:01:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:61374 https://access.redhat.com/errata/RHSA-2026:61374

Comment 15 errata-xmlrpc 2026-09-02 07:31:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:62416 https://access.redhat.com/errata/RHSA-2026:62416

Comment 16 errata-xmlrpc 2026-09-08 04:06:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:64817 https://access.redhat.com/errata/RHSA-2026:64817

Comment 17 Jon Orris 2026-09-16 17:17:43 UTC
This issue has been addressed in the following products:

  Cryostat 4 on RHEL 9

Via RHSA-2026:68333 https://access.redhat.com/errata/RHSA-2026:68333


Note You need to log in before you can comment on or make changes to this bug.