CVE-2019-18276
An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal to its real UID, it will drop privileges by setting its effective UID to its real UID. However, it does so incorrectly. On Linux and other systems that support "saved UID" functionality, the saved UID is not dropped. An attacker with command execution in the shell can use "enable -f" for runtime loading of a new builtin, which can be a shared object that calls setuid() and therefore regains privileges. However, binaries running with an effective UID of 0 are unaffected.
Published:Jul 1, 2019
Last Modified:Jun 9, 2025
EPS:Nov 28, 2019
EPSS Score:0.40022
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Gnu
Product
Bash
Gnu
Bash
Vendor
Netapp
Product
Hci Management Node
Netapp
Hci Management Node
Vendor
Netapp
Product
Oncommand Unified Manager
Netapp
Oncommand Unified Manager
Vendor
Netapp
Product
Solidfire
Netapp
Solidfire
Vendor
Oracle
Product
Communications Cloud Native Core Policy
Oracle
Communications Cloud Native Core Policy
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
