bash: parser can allow out-of-bounds memory access while handling redir_stack
Published Sep 28, 2014
10.0
HIGHCVSS 2.0
EPSS 69.78%
Description
The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted use of here documents, aka the "redir_stack" issue.
Affected products
No data.
- 1.14.0
- 1.14.1
- 1.14.2
- 1.14.3
- 1.14.4
- 1.14.5
- 1.14.6
- 1.14.7
- 2.0
- 2.01
- 2.01.1
- 2.02
- 2.02.1
- 2.03
- 2.04
- 2.05
- 2.05
- 2.05
- 3.0
- 3.0.16
- 3.1
- 3.2
- 3.2.48
- 4.0
- 4.0
- 4.1
- 4.2
- 4.3
No data.
RHEV Manager version 3.4
rhev-hypervisor6-0:6.5-20140930.1.el6ev
Fixed · RHSA-2014:1354
Red Hat Enterprise Linux 4 Extended Lifecycle Support
bash-0:3.0-27.el4.4
Fixed · RHSA-2014:1311
Red Hat Enterprise Linux 5
bash-0:3.2-33.el5_11.4
Fixed · RHSA-2014:1306
Red Hat Enterprise Linux 5.6 Long Life
bash-0:3.2-24.el5_6.2
Fixed · RHSA-2014:1311
Red Hat Enterprise Linux 5.9 Extended Update Support
bash-0:3.2-32.el5_9.3
Fixed · RHSA-2014:1311
Red Hat Enterprise Linux 6
bash-0:4.1.2-15.el6_5.2
Fixed · RHSA-2014:1306
Red Hat Enterprise Linux 6.2 Advanced Update Support
bash-0:4.1.2-9.el6_2.2
Fixed · RHSA-2014:1311
Red Hat Enterprise Linux 6.4 Extended Update Support
bash-0:4.1.2-15.el6_4.2
Fixed · RHSA-2014:1311
Red Hat Enterprise Linux 7
bash-0:4.2.45-5.el7_0.4
Fixed · RHSA-2014:1306
S-JIS for RHEL 5.9.Z
bash-0:3.2-32.el5_9.3.sjis.1
Fixed · RHSA-2014:1865
S-JIS for Red Hat Enteprise Linux 5
bash-0:3.2-33.el5_11.1.sjis.2
Fixed · RHSA-2014:1312
S-JIS for Red Hat Enteprise Linux 6
bash-0:4.1.2-15.el6_5.1.sjis.2
Fixed · RHSA-2014:1312
Red Hat Enterprise Linux 6
guest-images
Affected
Red Hat Enterprise Linux 7
rhel-guest-image
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEV Manager version 3.4 | rhev-hypervisor6-0:6.5-20140930.1.el6ev | Fixed | RHSA-2014:1354 |
| Red Hat Enterprise Linux 4 Extended Lifecycle Support | bash-0:3.0-27.el4.4 | Fixed | RHSA-2014:1311 |
| Red Hat Enterprise Linux 5 | bash-0:3.2-33.el5_11.4 | Fixed | RHSA-2014:1306 |
| Red Hat Enterprise Linux 5.6 Long Life | bash-0:3.2-24.el5_6.2 | Fixed | RHSA-2014:1311 |
| Red Hat Enterprise Linux 5.9 Extended Update Support | bash-0:3.2-32.el5_9.3 | Fixed | RHSA-2014:1311 |
| Red Hat Enterprise Linux 6 | bash-0:4.1.2-15.el6_5.2 | Fixed | RHSA-2014:1306 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | bash-0:4.1.2-9.el6_2.2 | Fixed | RHSA-2014:1311 |
| Red Hat Enterprise Linux 6.4 Extended Update Support | bash-0:4.1.2-15.el6_4.2 | Fixed | RHSA-2014:1311 |
| Red Hat Enterprise Linux 7 | bash-0:4.2.45-5.el7_0.4 | Fixed | RHSA-2014:1306 |
| S-JIS for RHEL 5.9.Z | bash-0:3.2-32.el5_9.3.sjis.1 | Fixed | RHSA-2014:1865 |
| S-JIS for Red Hat Enteprise Linux 5 | bash-0:3.2-33.el5_11.1.sjis.2 | Fixed | RHSA-2014:1312 |
| S-JIS for Red Hat Enteprise Linux 6 | bash-0:4.1.2-15.el6_5.1.sjis.2 | Fixed | RHSA-2014:1312 |
| Red Hat Enterprise Linux 6 | guest-images | Affected | n/a |
| Red Hat Enterprise Linux 7 | rhel-guest-image | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A patch for this issue was applied to the bash packages in Red Hat Enterprise Linux via RHSA-2014:1306, RHSA-2014:1311, and RHSA-2014:1312. The errata do not mention the CVE in the description, as the CVE was only assigned after those updates were released.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (46 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 69.78% (0.69784) | 99.35th | v5 (v2026.06.15) |
| Sep 20, 2026 | 65.97% (0.65974) | 99.24th | v5 (v2026.06.15) |
| Jun 15, 2026 | 64.34% (0.64336) | 99.13th | v5 (v2026.06.15) |
| Mar 4, 2026 | 90.17% (0.90174) | 99.58th | v4 (v2025.03.14) |
| Mar 1, 2026 | 88.28% (0.88283) | 99.49th | v4 (v2025.03.14) |
| Feb 4, 2026 | 91.01% (0.91010) | 99.62th | v4 (v2025.03.14) |
| Feb 1, 2026 | 89.48% (0.89484) | 99.54th | v4 (v2025.03.14) |
| Jan 21, 2026 | 91.01% (0.91010) | 99.62th | v4 (v2025.03.14) |
| Jan 4, 2026 | 89.66% (0.89656) | 99.54th | v4 (v2025.03.14) |
| Jan 1, 2026 | 87.62% (0.87619) | 99.45th | v4 (v2025.03.14) |
| Dec 4, 2025 | 89.66% (0.89656) | 99.53th | v4 (v2025.03.14) |
| Dec 1, 2025 | 87.62% (0.87619) | 99.44th | v4 (v2025.03.14) |
| Nov 4, 2025 | 89.66% (0.89656) | 99.53th | v4 (v2025.03.14) |
| Nov 1, 2025 | 87.62% (0.87619) | 99.44th | v4 (v2025.03.14) |
| Oct 4, 2025 | 89.66% (0.89656) | 99.53th | v4 (v2025.03.14) |
| Oct 1, 2025 | 87.62% (0.87619) | 99.44th | v4 (v2025.03.14) |
| Sep 4, 2025 | 90.34% (0.90345) | 99.58th | v4 (v2025.03.14) |
| Sep 1, 2025 | 88.60% (0.88597) | 99.49th | v4 (v2025.03.14) |
| Aug 4, 2025 | 90.34% (0.90345) | 99.57th | v4 (v2025.03.14) |
| Aug 1, 2025 | 88.60% (0.88597) | 99.49th | v4 (v2025.03.14) |
| Jul 4, 2025 | 90.34% (0.90345) | 99.57th | v4 (v2025.03.14) |
| Jul 1, 2025 | 88.60% (0.88597) | 99.48th | v4 (v2025.03.14) |
| Jun 6, 2025 | 90.34% (0.90345) | 99.56th | v4 (v2025.03.14) |
| Jun 4, 2025 | 89.08% (0.89083) | 99.50th | v4 (v2025.03.14) |
| Jun 1, 2025 | 86.81% (0.86807) | 99.39th | v4 (v2025.03.14) |
| May 15, 2025 | 89.08% (0.89083) | 99.49th | v4 (v2025.03.14) |
| May 11, 2025 | 86.81% (0.86807) | 99.37th | v4 (v2025.03.14) |
| May 4, 2025 | 89.08% (0.89083) | 99.48th | v4 (v2025.03.14) |
| May 1, 2025 | 86.81% (0.86807) | 99.38th | v4 (v2025.03.14) |
| Apr 17, 2025 | 89.08% (0.89083) | 99.48th | v4 (v2025.03.14) |
| Apr 16, 2025 | 86.81% (0.86807) | 99.36th | v4 (v2025.03.14) |
| Mar 31, 2025 | 89.08% (0.89083) | 99.51th | v4 (v2025.03.14) |
| Mar 30, 2025 | 86.81% (0.86807) | 99.39th | v4 (v2025.03.14) |
| Mar 29, 2025 | 84.55% (0.84545) | 99.16th | v4 (v2025.03.14) |
| Mar 22, 2025 | 89.08% (0.89083) | 99.53th | v4 (v2025.03.14) |
| Mar 21, 2025 | 86.81% (0.86807) | 99.41th | v4 (v2025.03.14) |
| Mar 17, 2025 | 89.08% (0.89083) | 99.51th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.48% (0.97480) | 99.98th | v3 (v2023.03.01) |
| Jun 24, 2024 | 97.47% (0.97467) | 99.96th | v3 (v2023.03.01) |
| May 10, 2024 | 97.49% (0.97494) | 99.98th | v3 (v2023.03.01) |
| Sep 5, 2023 | 97.51% (0.97510) | 99.97th | v3 (v2023.03.01) |
| Jul 19, 2023 | 97.52% (0.97521) | 99.97th | v3 (v2023.03.01) |
| Apr 23, 2023 | 97.53% (0.97527) | 99.98th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.54% (0.97536) | 99.98th | v3 (v2023.03.01) |
| Mar 6, 2023 | 84.57% (0.84572) | 99.65th | v2 (v2022.01.01) |
| Feb 4, 2022 | 84.57% (0.84572) | 99.58th | v2 (v2022.01.01) |
References (129)
- http://jvn.jp/en/jp/JVN55667175/index.html third-party-advisoryx_refsource_JVN
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126 third-party-advisoryx_refsource_JVNDB
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00038.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00041.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00042.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00044.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00048.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=141330468527613&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141345648114150&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383026420882&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383081521087&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383138121313&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383196021590&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383244821813&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141383304022067&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141450491804793&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141576728022234&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141577137423233&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141577241923505&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141577297623641&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141585637922673&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141694386919794&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=141879528318582&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142113462216480&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142118135300698&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142289270617409&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142358026505815&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142358078406056&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142721162228379&w=2 vendor-advisoryx_refsource_HP
- http://openwall.com/lists/oss-security/2014/09/25/32 mailing-listx_refsource_MLISTExploit
- http://openwall.com/lists/oss-security/2014/09/26/2 mailing-listx_refsource_MLIST
- http://openwall.com/lists/oss-security/2014/09/28/10 mailing-listx_refsource_MLIST
- http://packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.html x_refsource_MISC
- http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html x_refsource_MISC
- http://rhn.redhat.com/errata/RHSA-2014-1311.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2014-1312.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2014-1354.html vendor-advisoryx_refsource_REDHAT
- http://seclists.org/fulldisclosure/2014/Oct/0 mailing-listx_refsource_FULLDISC
- http://secunia.com/advisories/58200 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59907 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60024 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60034 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60044 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60055 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60063 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60193 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60433 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61065 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61128 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61129 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61188 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61283 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61287 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61291 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61312 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61313 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61328 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61442 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61471 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61479 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61485 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61503 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61550 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61552 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61565 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61603 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61618 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61622 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61633 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61636 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61641 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61643 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61654 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61703 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61711 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61780 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61816 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61873 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62228 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62312 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62343 third-party-advisoryx_refsource_SECUNIA
- http://support.apple.com/HT204244 x_refsource_CONFIRM
- http://support.novell.com/security/cve/CVE-2014-7186.html x_refsource_CONFIRM
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash vendor-advisoryx_refsource_CISCO
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021272 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021279 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021361 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004879 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004897 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004898 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004915 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21685541 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21685604 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21685733 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21685749 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21685914 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686084 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686131 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686246 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686445 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686447 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686479 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686494 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21687079 x_refsource_CONFIRM
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096315 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:164 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/support/kb/doc.php?id=7015721 x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/bashcve-2014-7169-2317675.html x_refsource_CONFIRM
- http://www.qnap.com/i/en/support/con_show.php?cid=61 x_refsource_CONFIRM
- http://www.securityfocus.com/archive/1/533593/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.ubuntu.com/usn/USN-2364-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vmware.com/security/advisories/VMSA-2014-0010.html x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2014-7186 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1146791 Issue Tracking
- https://kb.bluecoat.com/index?page=content&id=SA82 x_refsource_CONFIRM
- https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648 x_refsource_CONFIRM
- https://kc.mcafee.com/corporate/index?page=content&id=SB10085 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2014-7186
- https://support.apple.com/HT205267 x_refsource_CONFIRM
- https://support.citrix.com/article/CTX200217 x_refsource_CONFIRM
- https://support.citrix.com/article/CTX200223 x_refsource_CONFIRM
- https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15629.html x_refsource_CONFIRM
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04497075 x_refsource_CONFIRM
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04518183 x_refsource_CONFIRM
- https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102673&src=securityAlerts x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2014-7186
- https://www.suse.com/support/shellshock/ x_refsource_CONFIRM
Change history (0)
No recorded changes yet.