Executive brief
A vulnerability in the Bash command-line interpreter could allow a local user to crash the shell or potentially bypass security restrictions. By providing a specially crafted input to the 'popd' command, an attacker can cause the system to mishandle memory. This primarily impacts the availability of the shell session and could be used to escape restricted shell environments.
Technical details
A use-after-free vulnerability exists in the 'popd' builtin command of GNU Bash. The issue is located in the 'popd_builtin' function within 'pushd.def', where the shell fails to properly validate the index provided in a 'popd' command (e.g., 'popd +-111111'). This allows a local attacker to trigger a free() on an arbitrary or invalid memory address. Exploitation can lead to a denial of service (segmentation fault) or a bypass of restricted shell (rbash) configurations. The vulnerability is addressed in Bash 4.4 and various vendor backports.
Affected products
- GNU Bash up to 4.4-patch5
- Red Hat Enterprise Linux 6, 7
- Debian Debian Linux 8.0
Timeline
- 2016-11-17: disclosed: Public disclosure on oss-security mailing list
- 2016-11-17: advisory: CVE-2016-9401 assigned by MITRE
- 2017-01-23: advisory: NVD publication date
- 2017-03-21: patched: Red Hat released security updates (RHSA-2017:0725)
References
- http://rhn.redhat.com/errata/RHSA-2017-0725.html
- http://www.openwall.com/lists/oss-security/2016/11/17/5
- http://www.openwall.com/lists/oss-security/2016/11/17/9
- http://www.securityfocus.com/bid/94398
- https://access.redhat.com/errata/RHSA-2017:1931
- https://lists.debian.org/debian-lts-announce/2019/03/msg00028.html
- https://security.gentoo.org/glsa/201701-02