CVE-2014-7169
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Jan 28, 2022
- US federal agencies must remediate it by Jul 28, 2022 (BOD 22-01)
- First attack observed 5 days after disclosure
Apply updates per vendor instructions.
Source: CISA KEV · Mar 31, 2025 Jan 28, 2022 Mar 1, 2018 Sep 30, 2014
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| gnu | bash | <= 4.3 |
| arista | eos | < 4.9.12 |
| oracle | linux | 4 |
| qnap | qts | < 4.1.1 |
| mageia | mageia | 3.0 |
| redhat | gluster storage server for on-premise | 2.1 |
| redhat | virtualization | 3.4 |
| redhat | enterprise linux | 4.0 |
| redhat | enterprise linux desktop | 5.0 |
| redhat | enterprise linux eus | 5.9 |
| redhat | enterprise linux for ibm z systems | 5.9_s390x |
| redhat | enterprise linux for power big endian | 5.0_ppc |
| redhat | enterprise linux for power big endian eus | 6.5_ppc64 |
| redhat | enterprise linux for scientific computing | 6.0 |
| redhat | enterprise linux server | 5.0 |
| redhat | enterprise linux server aus | 5.6 |
| redhat | enterprise linux server from rhui | 5.0 |
| redhat | enterprise linux server tus | 6.5 |
| redhat | enterprise linux workstation | 5.0 |
| suse | studio onsite | 1.3 |
| opensuse | opensuse | 12.3 |
| suse | linux enterprise desktop | 11 |
| suse | linux enterprise server | 10 |
| suse | linux enterprise software development kit | 11 |
| debian | debian linux | 7.0 |
Related articles

CISA Adds ProFTPD, Struts, BIND, ONLYOFFICE and Strapi Flaws to KEV Over Flax Typhoon Abuse
CISA added ProFTPD, Struts, BIND, ONLYOFFICE and Strapi flaws to KEV following reported Flax Typhoon exploitation and joint advisory.

FBI Seizes Seven Domains Supporting Flax Typhoon Scanning and Malware Operations
FBI seized domains allegedly supporting MicroScan and FishHub scanning and malware platforms attributed to China-linked Flax Typhoon operators.
This product uses the NVD API but is not endorsed or certified by the NVD.