LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2014-6271

CVE-2014-6271

GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

CVSS 9.8 · CRITICAL ⚠ CISA KEV — ACTIVELY EXPLOITED
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2022-01-28. Federal remediation due 2022-07-28.
Required action: Apply updates per vendor instructions.

Summary

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

CVSS 3.1 breakdown

Base score9.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH

Weakness type (CWE)

Affected products

Gnu bashArista eosOracle linuxQnap qtsMageia mageiaRedhat gluster storage server for on-premiseRedhat virtualizationRedhat enterprise linuxRedhat enterprise linux desktopRedhat enterprise linux eusRedhat enterprise linux for ibm z systemsRedhat enterprise linux for power big endianRedhat enterprise linux for power big endian eusRedhat enterprise linux for scientific computingRedhat enterprise linux serverRedhat enterprise linux server ausRedhat enterprise linux server from rhuiRedhat enterprise linux server tusRedhat enterprise linux workstationSuse studio onsite
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD + CISA KEV. NVD last modified 2026-04-22. Always verify against the vendor advisory before acting.

Scroll to Top