A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade bash-develUpgrade bash | Jan 26, 2023 | Jan 5, 2023 |
| Amazon_linux_2023 | — | Upgrade bash-debugsourceUpgrade bash-docUpgrade bash-develUpgrade bash-debuginfoUpgrade bash | Feb 17, 2025 | Oct 27, 2022 |
| Centos_linux | — | Upgrade bash-debugsourceUpgrade bash-debuginfoUpgrade bash | Jan 24, 2023 | Jan 5, 2023 |
| Debian | — | Upgrade bash | Jul 30, 2024 | Jan 5, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade bash | Jan 6, 2023 | Jan 5, 2023 |
| Oracle_linux | — | Upgrade bashUpgrade bash-devel | Jan 24, 2023 | Oct 27, 2022 |
| Redhat_linux | — | Upgrade bash-debuginfoUpgrade bashUpgrade bash-develUpgrade bash-debugsourceNo solution exists | Jan 24, 2023 | Jan 5, 2023 |
| Rocky_linux | — | Upgrade bash-develUpgrade bash-debuginfoUpgrade bashUpgrade bash-debugsource | Mar 12, 2024 | Jan 5, 2023 |
| Ubuntu | — | Upgrade bash | Mar 19, 2024 | Jan 5, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub