Vulnerability record · CVE-2014-7187 · published 28 September 2014
CVE-2014-7187: GNU Bash off-by-one in read_token_word causes crash
Gnu · Bash
GNU Bash through 4.3 bash43-026 contains an off-by-one error in the read_token_word function in parse.y, the 'word_lineno' issue. Deeply nested for loops trigger an out-of-bounds array access that crashes the application. The record notes possible unspecified other impact but provides no further detail.
Description
Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityNetwork-reachable, unauthenticated crash with a very high EPSS percentile, though no confirmed code execution or KEV listing.
What it is
GNU Bash through 4.3 bash43-026 contains an off-by-one error in the read_token_word function in parse.y, the 'word_lineno' issue. Deeply nested for loops trigger an out-of-bounds array access that crashes the application. The record notes possible unspecified other impact but provides no further detail.
Impact
An attacker can cause a denial of service through an application crash. The description also mentions possible unspecified other impact, but no code execution or data compromise is confirmed.
Attack surface
Reachable remotely over the network with no authentication and no user interaction, per the AV:N/AC:L/Au:N/C:C/I:C/A:C vector. The trigger is crafted deeply nested for loops processed by Bash.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is 0.58462 (99.055th percentile), indicating high predicted exploitation activity.
What to do
- Patch Bash to a version after 4.3 bash43-026 using the vendor advisories referenced in the record.
- Apply the OpenSSL, Apple and openSUSE updates listed in the references for affected distributions.
- Restrict or sanitize untrusted input that reaches Bash parsing, especially deeply nested loop constructs.
- Monitor for abnormal Bash process crashes and repeated parse failures on exposed services.
Detection
- Alert on Bash process crashes or core dumps tied to parsing deeply nested for loops.
- Search application and system logs for repeated Bash parse errors or out-of-bounds access indicators.
- Track unpatched Bash versions across hosts and flag those at or below 4.3 bash43-026.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-7187 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-7187), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.