CVE-2019-18276
bash: when effective UID is not equal to its real UID the saved UID is not dropped
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal to its real UID, it will drop privileges by setting its effective UID to its real UID. However, it does so incorrectly. On Linux and other systems that support "saved UID" functionality, the saved UID is not dropped. An attacker with command execution in the shell can use "enable -f" for runtime loading of a new builtin, which can be a shared object that calls setuid() and therefore regains privileges. However, binaries running with an effective UID of 0 are unaffected.
Se descubrió un problema en la función disable_priv_mode en el archivo shell.c en GNU Bash versiones hasta la versión 5.0 parche 11. Por defecto, si Bash es ejecutado con su UID efectivo no igual a su UID real, perderá privilegios al establecer su UID efectivo en su UID real. Sin embargo, lo hace incorrectamente. En Linux y otros sistemas que admiten la funcionalidad "saved UID", el UID guardado no se descarta. Un atacante con ejecución de comando en el shell puede utilizar "enable -f" para la carga del tiempo de ejecución un nuevo builtin, que puede ser un objeto compartido que llama a setuid() y, por lo tanto, recupera privilegios. Sin embargo, los archivos binarios que son ejecutados con un UID efectivo de 0 no están afectados.
A privilege escalation vulnerability was found in bash in the way it dropped privileges when started with an effective user id not equal to the real user id. Bash may be vulnerable to this flaw if the setuid permission is set and the owner of the bash program itself is a non-root user. A local attacker could exploit this flaw to escalate their privileges on the system.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-10-23 CVE Reserved
- 2019-11-28 CVE Published
- 2021-12-09 First Exploit
- 2023-11-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-271: Privilege Dropping / Lowering Errors
- CWE-273: Improper Check for Dropped Privileges
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E | Mailing List | |
https://security.netapp.com/advisory/ntap-20200430-0003 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/M-ensimag/CVE-2019-18276 | 2021-12-09 | |
https://github.com/SABI-Ensimag/CVE-2019-18276 | 2022-02-01 | |
http://packetstormsecurity.com/files/155498/Bash-5.0-Patch-11-Privilege-Escalation.html | 2024-08-05 | |
https://www.youtube.com/watch?v=-wGtxJ8opa8 | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://github.com/bminor/bash/commit/951bdaad7a18cc0dc1036bba86b18b90874d39ff | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpuapr2022.html | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/202105-34 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2019-18276 | 2021-05-18 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1778309 | 2021-05-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnu Search vendor "Gnu" | Bash Search vendor "Gnu" for product "Bash" | <= 5.0 Search vendor "Gnu" for product "Bash" and version " <= 5.0" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Bash Search vendor "Gnu" for product "Bash" | 5.0 Search vendor "Gnu" for product "Bash" and version "5.0" | beta1 |
Affected
| ||||||
Gnu Search vendor "Gnu" | Bash Search vendor "Gnu" for product "Bash" | 5.0 Search vendor "Gnu" for product "Bash" and version "5.0" | beta2 |
Affected
| ||||||
Gnu Search vendor "Gnu" | Bash Search vendor "Gnu" for product "Bash" | 5.0 Search vendor "Gnu" for product "Bash" and version "5.0" | patch1 |
Affected
| ||||||
Gnu Search vendor "Gnu" | Bash Search vendor "Gnu" for product "Bash" | 5.0 Search vendor "Gnu" for product "Bash" and version "5.0" | patch10 |
Affected
| ||||||
Gnu Search vendor "Gnu" | Bash Search vendor "Gnu" for product "Bash" | 5.0 Search vendor "Gnu" for product "Bash" and version "5.0" | patch11 |
Affected
| ||||||
Gnu Search vendor "Gnu" | Bash Search vendor "Gnu" for product "Bash" | 5.0 Search vendor "Gnu" for product "Bash" and version "5.0" | patch2 |
Affected
| ||||||
Gnu Search vendor "Gnu" | Bash Search vendor "Gnu" for product "Bash" | 5.0 Search vendor "Gnu" for product "Bash" and version "5.0" | patch3 |
Affected
| ||||||
Gnu Search vendor "Gnu" | Bash Search vendor "Gnu" for product "Bash" | 5.0 Search vendor "Gnu" for product "Bash" and version "5.0" | patch4 |
Affected
| ||||||
Gnu Search vendor "Gnu" | Bash Search vendor "Gnu" for product "Bash" | 5.0 Search vendor "Gnu" for product "Bash" and version "5.0" | patch5 |
Affected
| ||||||
Gnu Search vendor "Gnu" | Bash Search vendor "Gnu" for product "Bash" | 5.0 Search vendor "Gnu" for product "Bash" and version "5.0" | patch6 |
Affected
| ||||||
Gnu Search vendor "Gnu" | Bash Search vendor "Gnu" for product "Bash" | 5.0 Search vendor "Gnu" for product "Bash" and version "5.0" | patch7 |
Affected
| ||||||
Gnu Search vendor "Gnu" | Bash Search vendor "Gnu" for product "Bash" | 5.0 Search vendor "Gnu" for product "Bash" and version "5.0" | patch8 |
Affected
| ||||||
Gnu Search vendor "Gnu" | Bash Search vendor "Gnu" for product "Bash" | 5.0 Search vendor "Gnu" for product "Bash" and version "5.0" | patch9 |
Affected
| ||||||
Gnu Search vendor "Gnu" | Bash Search vendor "Gnu" for product "Bash" | 5.0 Search vendor "Gnu" for product "Bash" and version "5.0" | rc1 |
Affected
| ||||||
Netapp Search vendor "Netapp" | Hci Management Node Search vendor "Netapp" for product "Hci Management Node" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Oncommand Unified Manager Search vendor "Netapp" for product "Oncommand Unified Manager" | >= 9.5 Search vendor "Netapp" for product "Oncommand Unified Manager" and version " >= 9.5" | vmware_vsphere |
Affected
| ||||||
Netapp Search vendor "Netapp" | Solidfire Search vendor "Netapp" for product "Solidfire" | - | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Cloud Native Core Policy Search vendor "Oracle" for product "Communications Cloud Native Core Policy" | 1.14.0 Search vendor "Oracle" for product "Communications Cloud Native Core Policy" and version "1.14.0" | - |
Affected
|