bash: when effective UID is not equal to its real UID the saved UID is not dropped
Published Nov 28, 2019
7.8
HIGHCVSS 3.1
EPSS 2.61%
Description
An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal to its real UID, it will drop privileges by setting its effective UID to its real UID. However, it does so incorrectly. On Linux and other systems that support "saved UID" functionality, the saved UID is not dropped. An attacker with command execution in the shell can use "enable -f" for runtime loading of a new builtin, which can be a shared object that calls setuid() and therefore regains privileges. However, binaries running with an effective UID of 0 are unaffected.
Affected products
No data.
Configuration 1
- ≤ 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
Configuration 2
- n/a
- ≥ 9.5
- n/a
Configuration 3
- 1.14.0
No data.
Red Hat Enterprise Linux 8
bash-0:4.4.19-14.el8
Fixed · RHSA-2021:1679
Red Hat Enterprise Linux 5
bash
Out of support scope
Red Hat Enterprise Linux 6
bash
Out of support scope
Red Hat Enterprise Linux 7
bash
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | bash-0:4.4.19-14.el8 | Fixed | RHSA-2021:1679 |
| Red Hat Enterprise Linux 5 | bash | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | bash | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | bash | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jun 9, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (22 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.61% (0.02608) | 84.85th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.61% (0.02608) | 83.33th | v5 (v2026.06.15) |
| Nov 24, 2025 | 49.61% (0.49613) | 97.66th | v4 (v2025.03.14) |
| Nov 21, 2025 | 43.87% (0.43873) | 97.37th | v4 (v2025.03.14) |
| Nov 18, 2025 | 22.51% (0.22509) | 95.46th | v4 (v2025.03.14) |
| Nov 16, 2025 | 44.49% (0.44493) | 97.41th | v4 (v2025.03.14) |
| Mar 30, 2025 | 39.41% (0.39410) | 97.00th | v4 (v2025.03.14) |
| Mar 29, 2025 | 54.82% (0.54822) | 97.16th | v4 (v2025.03.14) |
| Mar 28, 2025 | 39.41% (0.39410) | 97.00th | v4 (v2025.03.14) |
| Mar 27, 2025 | 54.82% (0.54822) | 97.71th | v4 (v2025.03.14) |
| Mar 20, 2025 | 40.00% (0.39995) | 97.07th | v4 (v2025.03.14) |
| Mar 19, 2025 | 55.39% (0.55386) | 97.78th | v4 (v2025.03.14) |
| Mar 17, 2025 | 40.00% (0.39995) | 97.00th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.15% (0.00153) | 52.94th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.11% (0.00108) | 43.36th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.10% (0.00102) | 40.07th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.08% (0.04082) | 85.99th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.13% (0.03130) | 65.01th | v2 (v2022.01.01) |
| Feb 3, 2022 | 10.45% (0.10445) | 87.57th | v1 |
| Jan 6, 2022 | 10.45% (0.10445) | 87.43th | v1 |
| Jan 5, 2022 | 2.53% (0.02534) | 79.46th | v5 (v2026.06.15) |
| Apr 14, 2021 | 2.18% (0.02177) | 0.00th | v1 |
References (11)
- http://packetstormsecurity.com/files/155498/Bash-5.0-Patch-11-Privilege-Escalation.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2019-18276 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1778309 Issue Tracking
- https://github.com/bminor/bash/commit/951bdaad7a18cc0dc1036bba86b18b90874d39ff x_refsource_CONFIRMPatchThird Party Advisory
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2019-18276
- https://security.gentoo.org/glsa/202105-34 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200430-0003/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-18276
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.youtube.com/watch?v=-wGtxJ8opa8 x_refsource_MISCExploitThird Party Advisory
Change history (0)
No recorded changes yet.