The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1345