https://seclists.org/oss-sec/2026/q1/122: Clarification: rbash escape via history built-ins
Published Jan 27, 2026
·Updated
Affected Software
1 affected component
GNU Bash=rbash
Frequently Asked Questions
1
What is the severity of CVE-2026-XXXX?
The severity of CVE-2026-XXXX is considered to be medium, as it allows users to escape restricted Bash confinement.
2
How do I fix CVE-2026-XXXX?
To fix CVE-2026-XXXX, restrict user permissions to prevent writing to startup files in the user home directory.
3
What systems are affected by CVE-2026-XXXX?
CVE-2026-XXXX affects systems running Restricted Bash (rbash) in GNU Bash.
4
Can CVE-2026-XXXX lead to unauthorized access?
Yes, CVE-2026-XXXX can lead to unauthorized access by allowing users to modify their environment and escape restrictions.
5
What are the implications of CVE-2026-XXXX for system security?
CVE-2026-XXXX has implications for system security as it can potentially allow a restricted user to gain elevated privileges.