// For flags

CVE-2019-18276

bash: when effective UID is not equal to its real UID the saved UID is not dropped

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal to its real UID, it will drop privileges by setting its effective UID to its real UID. However, it does so incorrectly. On Linux and other systems that support "saved UID" functionality, the saved UID is not dropped. An attacker with command execution in the shell can use "enable -f" for runtime loading of a new builtin, which can be a shared object that calls setuid() and therefore regains privileges. However, binaries running with an effective UID of 0 are unaffected.

Se descubrió un problema en la función disable_priv_mode en el archivo shell.c en GNU Bash versiones hasta la versión 5.0 parche 11. Por defecto, si Bash es ejecutado con su UID efectivo no igual a su UID real, perderá privilegios al establecer su UID efectivo en su UID real. Sin embargo, lo hace incorrectamente. En Linux y otros sistemas que admiten la funcionalidad "saved UID", el UID guardado no se descarta. Un atacante con ejecución de comando en el shell puede utilizar "enable -f" para la carga del tiempo de ejecución un nuevo builtin, que puede ser un objeto compartido que llama a setuid() y, por lo tanto, recupera privilegios. Sin embargo, los archivos binarios que son ejecutados con un UID efectivo de 0 no están afectados.

A privilege escalation vulnerability was found in bash in the way it dropped privileges when started with an effective user id not equal to the real user id. Bash may be vulnerable to this flaw if the setuid permission is set and the owner of the bash program itself is a non-root user. A local attacker could exploit this flaw to escalate their privileges on the system.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-10-23 CVE Reserved
  • 2019-11-28 CVE Published
  • 2021-12-09 First Exploit
  • 2023-11-08 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-271: Privilege Dropping / Lowering Errors
  • CWE-273: Improper Check for Dropped Privileges
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Gnu
Search vendor "Gnu"
Bash
Search vendor "Gnu" for product "Bash"
<= 5.0
Search vendor "Gnu" for product "Bash" and version " <= 5.0"
-
Affected
Gnu
Search vendor "Gnu"
Bash
Search vendor "Gnu" for product "Bash"
5.0
Search vendor "Gnu" for product "Bash" and version "5.0"
beta1
Affected
Gnu
Search vendor "Gnu"
Bash
Search vendor "Gnu" for product "Bash"
5.0
Search vendor "Gnu" for product "Bash" and version "5.0"
beta2
Affected
Gnu
Search vendor "Gnu"
Bash
Search vendor "Gnu" for product "Bash"
5.0
Search vendor "Gnu" for product "Bash" and version "5.0"
patch1
Affected
Gnu
Search vendor "Gnu"
Bash
Search vendor "Gnu" for product "Bash"
5.0
Search vendor "Gnu" for product "Bash" and version "5.0"
patch10
Affected
Gnu
Search vendor "Gnu"
Bash
Search vendor "Gnu" for product "Bash"
5.0
Search vendor "Gnu" for product "Bash" and version "5.0"
patch11
Affected
Gnu
Search vendor "Gnu"
Bash
Search vendor "Gnu" for product "Bash"
5.0
Search vendor "Gnu" for product "Bash" and version "5.0"
patch2
Affected
Gnu
Search vendor "Gnu"
Bash
Search vendor "Gnu" for product "Bash"
5.0
Search vendor "Gnu" for product "Bash" and version "5.0"
patch3
Affected
Gnu
Search vendor "Gnu"
Bash
Search vendor "Gnu" for product "Bash"
5.0
Search vendor "Gnu" for product "Bash" and version "5.0"
patch4
Affected
Gnu
Search vendor "Gnu"
Bash
Search vendor "Gnu" for product "Bash"
5.0
Search vendor "Gnu" for product "Bash" and version "5.0"
patch5
Affected
Gnu
Search vendor "Gnu"
Bash
Search vendor "Gnu" for product "Bash"
5.0
Search vendor "Gnu" for product "Bash" and version "5.0"
patch6
Affected
Gnu
Search vendor "Gnu"
Bash
Search vendor "Gnu" for product "Bash"
5.0
Search vendor "Gnu" for product "Bash" and version "5.0"
patch7
Affected
Gnu
Search vendor "Gnu"
Bash
Search vendor "Gnu" for product "Bash"
5.0
Search vendor "Gnu" for product "Bash" and version "5.0"
patch8
Affected
Gnu
Search vendor "Gnu"
Bash
Search vendor "Gnu" for product "Bash"
5.0
Search vendor "Gnu" for product "Bash" and version "5.0"
patch9
Affected
Gnu
Search vendor "Gnu"
Bash
Search vendor "Gnu" for product "Bash"
5.0
Search vendor "Gnu" for product "Bash" and version "5.0"
rc1
Affected
Netapp
Search vendor "Netapp"
Hci Management Node
Search vendor "Netapp" for product "Hci Management Node"
--
Affected
Netapp
Search vendor "Netapp"
Oncommand Unified Manager
Search vendor "Netapp" for product "Oncommand Unified Manager"
>= 9.5
Search vendor "Netapp" for product "Oncommand Unified Manager" and version " >= 9.5"
vmware_vsphere
Affected
Netapp
Search vendor "Netapp"
Solidfire
Search vendor "Netapp" for product "Solidfire"
--
Affected
Oracle
Search vendor "Oracle"
Communications Cloud Native Core Policy
Search vendor "Oracle" for product "Communications Cloud Native Core Policy"
1.14.0
Search vendor "Oracle" for product "Communications Cloud Native Core Policy" and version "1.14.0"
-
Affected