https://seclists.org/oss-sec/2026/q1/128: Clarification: rbash escape via history built-ins
Published Jan 28, 2026
·Updated
Affected Software
1 affected component
GNU Bash
Frequently Asked Questions
1
What is the severity of the vulnerability ID CVE-2026-XXXX?
The vulnerability ID CVE-2026-XXXX is considered high due to its potential to allow users to escape restricted shell environments.
2
How do I fix the vulnerability ID CVE-2026-XXXX?
To fix the vulnerability ID CVE-2026-XXXX, users should update their GNU Bash to the latest version available.
3
What are the affected versions for vulnerability ID CVE-2026-XXXX?
The affected versions for vulnerability ID CVE-2026-XXXX include all versions of GNU Bash prior to the patch released after January 28, 2026.
4
What types of systems are at risk from vulnerability ID CVE-2026-XXXX?
Systems using GNU Bash in a restricted mode, particularly those that do not properly manage user history files, are at risk from vulnerability ID CVE-2026-XXXX.
5
Is user data at risk due to vulnerability ID CVE-2026-XXXX?
Yes, user data may be at risk because the vulnerability allows potentially malicious users to overwrite startup files in their home directory.