← Vulnerability feed

Vulnerability record · CVE-2014-6278 · published 30 September 2014

CVE-2014-6278: GNU Bash environment function parsing command injection

Gnu · Bash

GNU Bash through 4.3 bash43-026 fails to properly parse function definitions in environment variable values, allowing command injection when the environment crosses a privilege boundary. It is an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277, so systems patched only for the earlier Shellshock flaws may still be exposed.

8.8 CVSS 3.1 High CISA KEV since 2 Oct 2025 EPSS 100% · top 0.1% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
221References
17 Jun 2026Last modified by NVD

Description

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with a near-maximum EPSS score and allows unauthenticated remote command execution, though the CVSS vector requires user interaction.

What it is

GNU Bash through 4.3 bash43-026 fails to properly parse function definitions in environment variable values, allowing command injection when the environment crosses a privilege boundary. It is an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277, so systems patched only for the earlier Shellshock flaws may still be exposed.

Impact

An attacker can execute arbitrary commands with the privileges of the process that invokes Bash, potentially leading to full host compromise. The CVSS 3.1 vector rates confidentiality, integrity, and availability impact as high.

Attack surface

Reachable remotely over the network (AV:N) with no privileges required (PR:N), but user interaction is required (UI:R) per the CVSS vector. The description cites OpenSSH ForceCommand, Apache mod_cgi/mod_cgid, and DHCP client scripts as paths where environment variables are set across a privilege boundary before Bash runs.

Exploitation

CISA added it to the KEV catalog on 2025-10-02 with a due date of 2025-10-23, and EPSS gives a 30-day probability of 0.9952 (99.9th percentile), indicating active exploitation is expected. No ransomware campaign use is documented in the record.

What to do

  • Patch Bash to a version that fully addresses CVE-2014-6271, CVE-2014-7169, CVE-2014-6277, and CVE-2014-6278; apply vendor errata rather than the earlier partial fixes.
  • Follow CISA KEV required action and BOD 22-01 guidance for cloud services, or discontinue use of the affected product if mitigations are unavailable.
  • Reduce exposure by avoiding untrusted environment variables crossing privilege boundaries into Bash, and review CGI, SSH ForceCommand, and DHCP client script configurations.
  • Where patching is delayed, restrict network access to services that pass environment data to Bash and monitor for anomalous child processes.

Detection

  • Monitor for Bash processes spawned by web servers (mod_cgi/mod_cgid), sshd ForceCommand, or DHCP clients with unexpected command arguments or child processes.
  • Alert on environment variables containing function-definition syntax such as '() {' passed into Bash invocations.
  • Hunt for outbound connections or file writes originating from CGI, SSH, or DHCP service accounts shortly after request handling.
  • Track Bash package versions across hosts and flag any still at or below 4.3 bash43-026.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2014-6278 to the Known Exploited Vulnerabilities catalog on 2 October 2025 as "GNU Bash OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 October 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://jvn.jp/en/jp/JVN55667175/index.html Third Party Advisory
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126 Third Party Advisory
http://lcamtuf.blogspot.com/2014/09/bash-bug-apply-unofficial-patch-now.html PatchThird Party Advisory
http://lcamtuf.blogspot.com/2014/10/bash-bug-how-we-finally-cracked.html Third Party Advisory
http://linux.oracle.com/errata/ELSA-2014-3093 Third Party Advisory
http://linux.oracle.com/errata/ELSA-2014-3094 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00004.html Mailing List
http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.html Mailing List
http://marc.info/?l=bugtraq&m=141330468527613&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141345648114150&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141383026420882&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141383081521087&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141383196021590&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141383244821813&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141383304022067&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141383353622268&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141383465822787&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141450491804793&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141576728022234&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141577137423233&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141577241923505&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141577297623641&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141585637922673&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141879528318582&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=142118135300698&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=142358026505815&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=142358078406056&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=142721162228379&w=2 Third Party Advisory
http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html Third Party Advisory
http://packetstormsecurity.com/files/137344/Sun-Secure-Global-Desktop-Oracle-Global-Desktop-Shellshock.html Third Party Advisory
http://secunia.com/advisories/58200 Broken Link
http://secunia.com/advisories/59907 Broken Link
http://secunia.com/advisories/59961 Broken Link
http://secunia.com/advisories/60024 Broken Link
http://secunia.com/advisories/60034 Broken Link
http://secunia.com/advisories/60044 Broken Link
http://secunia.com/advisories/60055 Broken Link
http://secunia.com/advisories/60063 Broken Link
http://secunia.com/advisories/60193 Broken Link
http://secunia.com/advisories/60325 Broken Link

Track CVE-2014-6278 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed10.0CVE-2014-7186GNU Bash redirection stack out-of-bounds access via here documentsThe redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 mishandles here documents, causing an out-of-bounds array access in the …EPSS 66%analysed10.0CVE-2014-7187GNU Bash off-by-one in read_token_word causes crashGNU Bash through 4.3 bash43-026 contains an off-by-one error in the read_token_word function in parse.y, the 'word_lineno' issue. Deeply nested for l…EPSS 65%analysed10.0CVE-2014-6277GNU Bash environment function parsing flaw allows command executionGNU Bash through 4.3 bash43-026 fails to properly parse function definitions in environment variable values, allowing crafted environments to trigger…EPSS 70%analysed8.4CVE-2016-7543Gnu bash improper input validation vulnerabilityBash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.EPSS 0.58%7.8CVE-2022-3715Gnu bash memory buffer overflow vulnerabilityA flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems.EPSS 0.36%7.8CVE-2019-18276Gnu bash vulnerabilityAn issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2014-6278), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.