CVE-2026-102474
Received Received - Intake

Dash printf Unicode Escape Memory Corruption

Vulnerability report for CVE-2026-102474, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: redhat-SADP

Description

A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \u or \U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past that reservation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
debian dash to 2026-09-29 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-102474 is a flaw in the dash shell where the printf builtin reserves only four bytes for Unicode escape sequences like \u or \U. These sequences can require five or six bytes, causing a heap out-of-bounds write when a local user supplies such an escape to dash printf, echo %b, or dash -c with a positional argument.

Detection Guidance

To detect this vulnerability, check if your system uses an affected version of dash. Run 'dash --version' to identify the shell version. If dash is installed, inspect whether it is the default shell or used in scripts. Look for processes using dash, especially those handling user input like printf or echo %b. Commands like 'ps aux | grep dash' or 'lsof | grep dash' may help identify usage patterns.

Impact Analysis

This vulnerability could allow a local attacker to corrupt heap memory, potentially causing crashes or unexpected behavior in the dash shell. It does not directly escalate privileges but may lead to memory corruption or application instability if exploited.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR or HIPAA as it does not involve unauthorized data access, disclosure, or loss of availability. The flaw primarily causes memory corruption through heap out-of-bounds writes, which could lead to crashes or unexpected behavior but does not inherently violate data protection requirements under these standards.

Mitigation Strategies

Avoid passing untrusted data into dash printf, echo %b, or dash -c commands. Update dash to a patched version if available. If dash is not the default shell, consider removing it or restricting its use. Monitor system logs for crashes or memory corruption errors that may indicate exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102474. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart