← Vulnerability feed

Vulnerability record · CVE-2014-7186 · published 28 September 2014

CVE-2014-7186: GNU Bash redirection stack out-of-bounds access via here documents

Gnu · Bash

The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 mishandles here documents, causing an out-of-bounds array access in the redirection stack (the "redir_stack" issue). A remote attacker can crash the shell or possibly achieve unspecified other impact. Because Bash is widely deployed and often processes untrusted input, this is a serious availability and potential integrity risk.

10.0 CVSS 2.0 High EPSS 66% · top 0.7% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
250References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted use of here documents, aka the "redir_stack" issue.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 2.0 score of 10 with a network, unauthenticated vector and very high EPSS probability, though no KEV listing or confirmed in-the-wild exploitation is recorded.

What it is

The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 mishandles here documents, causing an out-of-bounds array access in the redirection stack (the "redir_stack" issue). A remote attacker can crash the shell or possibly achieve unspecified other impact. Because Bash is widely deployed and often processes untrusted input, this is a serious availability and potential integrity risk.

Impact

An attacker can cause a denial of service by crashing the Bash process, and the out-of-bounds access may allow further unspecified impact such as memory corruption. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.

Attack surface

Reachable remotely over the network with no authentication and no user interaction per the AV:N/AC:L/Au:N vector, by supplying crafted here-document content that Bash parses. Any service or script that passes attacker-controlled text into Bash redirection parsing is exposed.

Exploitation

Not listed in CISA KEV and no ransomware group usage is documented, but EPSS is high at 0.64336 (99.2nd percentile), indicating elevated likelihood of exploitation activity. Reference tags are empty, so no vendor or third-party confirmation of in-the-wild exploitation is provided.

What to do

  • Patch Bash to a version later than 4.3 bash43-026, or apply the vendor fix for the redir_stack issue; prioritize internet-facing and shared-host systems.
  • Avoid passing untrusted input into Bash here-document or redirection parsing; sanitize or reject crafted here-document content at application boundaries.
  • Restrict which users and services can invoke Bash with attacker-influenced arguments, and run such services with least privilege.
  • Monitor vendor advisories (Apple, openSUSE and others referenced) for updated packages and redeploy patched builds.

Detection

  • Monitor for Bash process crashes or abnormal termination correlated with here-document or redirection-heavy input.
  • Alert on repeated shell invocations containing here-document syntax from untrusted or remote-originating sources.
  • Audit application and CGI logs for crafted here-document payloads reaching Bash, and review core dumps for out-of-bounds access in parse.y redirection handling.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://jvn.jp/en/jp/JVN55667175/index.html
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126
http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html
http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00038.html
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00041.html
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00042.html
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00044.html
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00048.html
http://marc.info/?l=bugtraq&m=141330468527613&w=2
http://marc.info/?l=bugtraq&m=141345648114150&w=2
http://marc.info/?l=bugtraq&m=141383026420882&w=2
http://marc.info/?l=bugtraq&m=141383081521087&w=2
http://marc.info/?l=bugtraq&m=141383138121313&w=2
http://marc.info/?l=bugtraq&m=141383196021590&w=2
http://marc.info/?l=bugtraq&m=141383244821813&w=2
http://marc.info/?l=bugtraq&m=141383304022067&w=2
http://marc.info/?l=bugtraq&m=141450491804793&w=2
http://marc.info/?l=bugtraq&m=141576728022234&w=2
http://marc.info/?l=bugtraq&m=141577137423233&w=2
http://marc.info/?l=bugtraq&m=141577241923505&w=2
http://marc.info/?l=bugtraq&m=141577297623641&w=2
http://marc.info/?l=bugtraq&m=141585637922673&w=2
http://marc.info/?l=bugtraq&m=141694386919794&w=2
http://marc.info/?l=bugtraq&m=141879528318582&w=2
http://marc.info/?l=bugtraq&m=142113462216480&w=2
http://marc.info/?l=bugtraq&m=142118135300698&w=2
http://marc.info/?l=bugtraq&m=142289270617409&w=2
http://marc.info/?l=bugtraq&m=142358026505815&w=2
http://marc.info/?l=bugtraq&m=142358078406056&w=2
http://marc.info/?l=bugtraq&m=142721162228379&w=2
http://openwall.com/lists/oss-security/2014/09/25/32 Exploit
http://openwall.com/lists/oss-security/2014/09/26/2
http://openwall.com/lists/oss-security/2014/09/28/10
http://packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.html
http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html
http://rhn.redhat.com/errata/RHSA-2014-1311.html
http://rhn.redhat.com/errata/RHSA-2014-1312.html
http://rhn.redhat.com/errata/RHSA-2014-1354.html
http://seclists.org/fulldisclosure/2014/Oct/0

Track CVE-2014-7186 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed8.8CVE-2014-6278GNU Bash environment function parsing command injectionGNU Bash through 4.3 bash43-026 fails to properly parse function definitions in environment variable values, allowing command injection when the envi…KEVEPSS 100%analysed10.0CVE-2014-7187GNU Bash off-by-one in read_token_word causes crashGNU Bash through 4.3 bash43-026 contains an off-by-one error in the read_token_word function in parse.y, the 'word_lineno' issue. Deeply nested for l…EPSS 65%analysed10.0CVE-2014-6277GNU Bash environment function parsing flaw allows command executionGNU Bash through 4.3 bash43-026 fails to properly parse function definitions in environment variable values, allowing crafted environments to trigger…EPSS 70%analysed8.4CVE-2016-7543Gnu bash improper input validation vulnerabilityBash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.EPSS 0.58%7.8CVE-2022-3715Gnu bash memory buffer overflow vulnerabilityA flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems.EPSS 0.36%7.8CVE-2019-18276Gnu bash vulnerabilityAn issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2014-7186), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.