CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Jan 28, 2022
- US federal agencies must remediate it by Jul 28, 2022 (BOD 22-01)
- First attack observed 5 days after disclosure
- Confirmed by sensors, not only by reports
Apply updates per vendor instructions.
Source: CISA KEV · Oct 3, 2026 Sep 8, 2026 Sep 3, 2026 Aug 20, 2026 Jun 4, 2026 Mar 11, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| gnu | bash | <= 4.3 |
| arista | eos | < 4.9.12 |
| oracle | linux | 4 |
| qnap | qts | < 4.1.1 |
| mageia | mageia | 3.0 |
| redhat | gluster storage server for on-premise | 2.1 |
| redhat | virtualization | 3.4 |
| redhat | enterprise linux | 4.0 |
| redhat | enterprise linux desktop | 5.0 |
| redhat | enterprise linux eus | 5.9 |
| redhat | enterprise linux for ibm z systems | 5.9_s390x |
| redhat | enterprise linux for power big endian | 5.0_ppc |
| redhat | enterprise linux for power big endian eus | 6.5_ppc64 |
| redhat | enterprise linux for scientific computing | 6.0 |
| redhat | enterprise linux server | 5.0 |
| redhat | enterprise linux server aus | 5.6 |
| redhat | enterprise linux server from rhui | 5.0 |
| redhat | enterprise linux server tus | 6.5 |
| redhat | enterprise linux workstation | 5.0 |
| suse | studio onsite | 1.3 |
| opensuse | opensuse | 12.3 |
| suse | linux enterprise desktop | 11 |
| suse | linux enterprise server | 10 |
| suse | linux enterprise software development kit | 11 |
| debian | debian linux | 7.0 |
Related articles

CISA Adds ProFTPD, Struts, BIND, ONLYOFFICE and Strapi Flaws to KEV Over Flax Typhoon Abuse
CISA added ProFTPD, Struts, BIND, ONLYOFFICE and Strapi flaws to KEV following reported Flax Typhoon exploitation and joint advisory.

FBI Seizes Seven Domains Supporting Flax Typhoon Scanning and Malware Operations
FBI seized domains allegedly supporting MicroScan and FishHub scanning and malware platforms attributed to China-linked Flax Typhoon operators.
This product uses the NVD API but is not endorsed or certified by the NVD.