Bug 2510722 (CVE-2026-69152) - CVE-2026-69152 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
Summary: CVE-2026-69152 brace-expansion: DoS via unbounded intermediate arrays, bypass...
Keywords:
Status: NEW
Alias: CVE-2026-69152
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2511786 2511787 2511788 2511790 2511792 2511793 2511794 2511795 2511796 2511798 2511799 2511800 2511801 2511802 2511803 2511804 2511807 2511808 2511809 2511810 2511811 2511812 2511818 2511822 2511825 2511826 2511785 2511789 2511791 2511797 2511805 2511806 2511814 2511816 2511820 2511824
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-03 18:01 UTC by OSIDB Bzimport
Modified: 2026-08-15 08:27 UTC (History)
156 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:52841 0 None None None 2026-08-10 13:16:07 UTC
Red Hat Product Errata RHSA-2026:54371 0 None None None 2026-08-12 14:17:21 UTC
Red Hat Product Errata RHSA-2026:54530 0 None None None 2026-08-13 11:34:51 UTC

Description OSIDB Bzimport 2026-08-03 18:01:36 UTC
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.

Comment 3 errata-xmlrpc 2026-08-10 13:15:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:52841 https://access.redhat.com/errata/RHSA-2026:52841

Comment 4 errata-xmlrpc 2026-08-12 14:17:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:54371 https://access.redhat.com/errata/RHSA-2026:54371

Comment 5 errata-xmlrpc 2026-08-13 11:34:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:54530 https://access.redhat.com/errata/RHSA-2026:54530


Note You need to log in before you can comment on or make changes to this bug.