CVE detail
CVE-2014-6278: GNU Bash OS Command Injection Vulnerability
Source: CISA Known Exploited Vulnerabilities catalog · back to feed
Vendor / product
GNU · GNU Bash
- Date added (KEV)
- Oct 02, 2025
- CISA due date
- Oct 23, 2025
- Ransomware campaign use
- Unknown
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Vendor fix: Vendor advisory
Scorifya interpretation
AI-generatedA short, structured read of the record above, generated when this page first loads, then cached for a week.
Plain English
Technical detail
From CISA
GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.
This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: http://ftp.gnu.org/gnu/bash/bash-4.3-patches/bash43-027 ; https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23467 ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash ; https://www.ibm.com/support/pages/security-bulletin-update-vulnerabilities-bash-affect-aix-toolbox-linux-applications-cve-2014-6271-cve-2014-6277-cve-2014-6278-cve-2014-7169-cve-2014-7186-and-cve-2014-7187 ; https://nvd.nist.gov/vuln/detail/CVE-2014-6278
See what attackers can see on your domain
This vulnerability is on CISA's Known Exploited Vulnerabilities list, so it is being exploited in the wild right now. Scorifya can't test for GNU directly, but in about 30 seconds it shows what your own domain exposes publicly across TLS, security headers, DNS, and cookies: the surface attackers probe first.
SOC 2 compliance
Tracking remediation across your cloud infrastructure?
Scorifya Controls automates 54 SOC 2 checks across AWS, GitHub, GCP, and Azure, and gives you a manual evidence trail for the controls no tool can automate. Self-hosted, three tiers from $99/mo.
See Scorifya Controls →References
- https://www.suse.com/support/shellshock/Vendor Advisory
- https://www.suse.com/support/shellshock/Vendor Advisory
- http://lcamtuf.blogspot.com/2014/09/bash-bug-apply-unofficial-patch-now.htmlPatchThird Party Advisory
- http://lcamtuf.blogspot.com/2014/09/bash-bug-apply-unofficial-patch-now.htmlPatchThird Party Advisory
- http://jvn.jp/en/jp/JVN55667175/index.htmlThird Party Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126Third Party Advisory
- http://lcamtuf.blogspot.com/2014/10/bash-bug-how-we-finally-cracked.htmlThird Party Advisory
- http://linux.oracle.com/errata/ELSA-2014-3093Third Party Advisory
- http://linux.oracle.com/errata/ELSA-2014-3094Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00004.htmlMailing List
- http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.htmlMailing List
- http://marc.info/?l=bugtraq&m=141330468527613&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141345648114150&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141383026420882&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141383081521087&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141383196021590&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141383244821813&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141383304022067&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141383353622268&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141383465822787&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141450491804793&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141576728022234&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141577137423233&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141577241923505&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141577297623641&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141585637922673&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141879528318582&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=142118135300698&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=142358026505815&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=142358078406056&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=142721162228379&w=2Third Party Advisory
- http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.htmlThird Party Advisory
- http://packetstormsecurity.com/files/137344/Sun-Secure-Global-Desktop-Oracle-Global-Desktop-Shellshock.htmlThird Party Advisory
- http://secunia.com/advisories/58200Broken Link
- http://secunia.com/advisories/59907Broken Link
- http://secunia.com/advisories/59961Broken Link
- http://secunia.com/advisories/60024Broken Link
- http://secunia.com/advisories/60034Broken Link
- http://secunia.com/advisories/60044Broken Link
- http://secunia.com/advisories/60055Broken Link
- http://secunia.com/advisories/60063Broken Link
- http://secunia.com/advisories/60193Broken Link
- http://secunia.com/advisories/60325Broken Link
- http://secunia.com/advisories/60433Broken Link
- http://secunia.com/advisories/61065Broken Link
- http://secunia.com/advisories/61128Broken Link
- http://secunia.com/advisories/61129Broken Link
- http://secunia.com/advisories/61283Broken Link
- http://secunia.com/advisories/61287Broken Link
- http://secunia.com/advisories/61291Broken Link
- http://secunia.com/advisories/61312Broken Link
- http://secunia.com/advisories/61313Broken Link
- http://secunia.com/advisories/61328Broken Link
- http://secunia.com/advisories/61442Broken Link
- http://secunia.com/advisories/61471Broken Link
- http://secunia.com/advisories/61485Broken Link
- http://secunia.com/advisories/61503Broken Link
- http://secunia.com/advisories/61550Broken Link
- http://secunia.com/advisories/61552Broken Link
- http://secunia.com/advisories/61565Broken Link
- http://secunia.com/advisories/61603Broken Link
- http://secunia.com/advisories/61633Broken Link
- http://secunia.com/advisories/61641Broken Link
- http://secunia.com/advisories/61643Broken Link
- http://secunia.com/advisories/61654Broken Link
- http://secunia.com/advisories/61703Broken Link
- http://secunia.com/advisories/61780Broken Link
- http://secunia.com/advisories/61816Broken Link
- http://secunia.com/advisories/61857Broken Link
- http://secunia.com/advisories/62312Broken Link
- http://secunia.com/advisories/62343Third Party Advisory
- http://support.novell.com/security/cve/CVE-2014-6278.htmlThird Party Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bashThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021272Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021279Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021361Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004879Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004897Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004898Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004915Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21685541Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21685604Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21685733Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21685749Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21685914Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21686131Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21686246Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21686445Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21686479Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21686494Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21687079Third Party Advisory
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096315Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:164Third Party Advisory
- http://www.novell.com/support/kb/doc.php?id=7015721Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bashcve-2014-7169-2317675.htmlThird Party Advisory
- http://www.qnap.com/i/en/support/con_show.php?cid=61Third Party Advisory
- http://www.ubuntu.com/usn/USN-2380-1Third Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2014-0010.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1147414Third Party Advisory
- https://kb.bluecoat.com/index?page=content&id=SA82Third Party Advisory
- https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10085Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2014-6278Third Party Advisory
- https://support.citrix.com/article/CTX200217Third Party Advisory
- https://support.citrix.com/article/CTX200223Third Party Advisory
- https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15629.htmlThird Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04497075Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04518183Third Party Advisory
- https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102673&src=securityAlertsThird Party Advisory
- https://www.arista.com/en/support/advisories-notices/security-advisories/1008-security-advisory-0006Third Party Advisory
- https://www.exploit-db.com/exploits/39568/Third Party Advisory
- https://www.exploit-db.com/exploits/39887/Third Party Advisory
- http://jvn.jp/en/jp/JVN55667175/index.htmlThird Party Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126Third Party Advisory
- http://lcamtuf.blogspot.com/2014/10/bash-bug-how-we-finally-cracked.htmlThird Party Advisory
- http://linux.oracle.com/errata/ELSA-2014-3093Third Party Advisory
- http://linux.oracle.com/errata/ELSA-2014-3094Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00004.htmlMailing List
- http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.htmlMailing List
- http://marc.info/?l=bugtraq&m=141330468527613&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141345648114150&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141383026420882&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141383081521087&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141383196021590&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141383244821813&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141383304022067&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141383353622268&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141383465822787&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141450491804793&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141576728022234&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141577137423233&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141577241923505&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141577297623641&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141585637922673&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=141879528318582&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=142118135300698&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=142358026505815&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=142358078406056&w=2Third Party Advisory
- http://marc.info/?l=bugtraq&m=142721162228379&w=2Third Party Advisory
- http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.htmlThird Party Advisory
- http://packetstormsecurity.com/files/137344/Sun-Secure-Global-Desktop-Oracle-Global-Desktop-Shellshock.htmlThird Party Advisory
- http://secunia.com/advisories/58200Broken Link
- http://secunia.com/advisories/59907Broken Link
- http://secunia.com/advisories/59961Broken Link
- http://secunia.com/advisories/60024Broken Link
- http://secunia.com/advisories/60034Broken Link
- http://secunia.com/advisories/60044Broken Link
- http://secunia.com/advisories/60055Broken Link
- http://secunia.com/advisories/60063Broken Link
- http://secunia.com/advisories/60193Broken Link
- http://secunia.com/advisories/60325Broken Link
- http://secunia.com/advisories/60433Broken Link
- http://secunia.com/advisories/61065Broken Link
- http://secunia.com/advisories/61128Broken Link
- http://secunia.com/advisories/61129Broken Link
- http://secunia.com/advisories/61283Broken Link
- http://secunia.com/advisories/61287Broken Link
- http://secunia.com/advisories/61291Broken Link
- http://secunia.com/advisories/61312Broken Link
- http://secunia.com/advisories/61313Broken Link
- http://secunia.com/advisories/61328Broken Link
- http://secunia.com/advisories/61442Broken Link
- http://secunia.com/advisories/61471Broken Link
- http://secunia.com/advisories/61485Broken Link
- http://secunia.com/advisories/61503Broken Link
- http://secunia.com/advisories/61550Broken Link
- http://secunia.com/advisories/61552Broken Link
- http://secunia.com/advisories/61565Broken Link
- http://secunia.com/advisories/61603Broken Link
- http://secunia.com/advisories/61633Broken Link
- http://secunia.com/advisories/61641Broken Link
- http://secunia.com/advisories/61643Broken Link
- http://secunia.com/advisories/61654Broken Link
- http://secunia.com/advisories/61703Broken Link
- http://secunia.com/advisories/61780Broken Link
- http://secunia.com/advisories/61816Broken Link
- http://secunia.com/advisories/61857Broken Link
- http://secunia.com/advisories/62312Broken Link
- http://secunia.com/advisories/62343Third Party Advisory
- http://support.novell.com/security/cve/CVE-2014-6278.htmlThird Party Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bashThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021272Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021279Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021361Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004879Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004897Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004898Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004915Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21685541Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21685604Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21685733Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21685749Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21685914Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21686131Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21686246Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21686445Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21686479Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21686494Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21687079Third Party Advisory
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096315Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:164Third Party Advisory
- http://www.novell.com/support/kb/doc.php?id=7015721Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bashcve-2014-7169-2317675.htmlThird Party Advisory
- http://www.qnap.com/i/en/support/con_show.php?cid=61Third Party Advisory
- http://www.ubuntu.com/usn/USN-2380-1Third Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2014-0010.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1147414Third Party Advisory
- https://kb.bluecoat.com/index?page=content&id=SA82Third Party Advisory
- https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10085Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2014-6278Third Party Advisory
- https://support.citrix.com/article/CTX200217Third Party Advisory
- https://support.citrix.com/article/CTX200223Third Party Advisory
- https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15629.htmlThird Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04497075Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04518183Third Party Advisory
- https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102673&src=securityAlertsThird Party Advisory
- https://www.arista.com/en/support/advisories-notices/security-advisories/1008-security-advisory-0006Third Party Advisory
- https://www.exploit-db.com/exploits/39568/Third Party Advisory
- https://www.exploit-db.com/exploits/39887/Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-6278US Government Resource
Other recent CVEs from GNU
- CVE-2026-24061InetUtils, GNU InetUtils Argument Injection Vulnerability
- CVE-2023-4911GNU C Library, GNU C Library Buffer Overflow Vulnerability
- CVE-2014-6271Bourne-Again Shell (Bash), GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
- CVE-2014-7169Bourne-Again Shell (Bash), GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability