A privilege escalation vulnerability was found in bash in the way it dropped
privileges when started with an effective user id not equal to the real user
id. Bash may be vulnerable to this flaw if the setuid permission is set and
the owner of the bash program itself is a non-root user. A local attacker
could exploit this flaw to escalate their privileges on the system
(CVE-2019-18276).
- https://bugs.mageia.org/show_bug.cgi?id=28937
- https://access.redhat.com/errata/RHSA-2021:1679
- https://www.cve.org/CVERecord?id=CVE-2019-18276
- 7/core/bash-4.4-23.1.2.mga7
Get the latest Linux and open source security news straight to your inbox.