Re: [SECURITY] Async-signal-unsafe operations in alrm_catcher() signal handler

Chet Ramey <[email protected]>
Newsgroups gmane.comp.shells.bash.bugs
Organization ITS, Case Western Reserve University
Message-ID <[email protected]>
On 8/27/26 7:22 PM, correspondence2--- via Bug reports for the GNU Bourne 
Again SHell wrote:
> Dear GNU Bash Maintainers,
> 
> I am writing to report a security vulnerability in the GNU Bash shell.

Thanks for the report. This is not a bash vulnerability.

It's worthwhile to move the calls to async-unsafe functions out of a signal
handler execution path, similar to how the shell handles other signals.

-- 
``The lyf so short, the craft so long to lerne.'' - Chaucer
		 ``Ars longa, vita brevis'' - Hippocrates
Chet Ramey, UTech, CWRU    [email protected]    http://tiswww.cwru.edu/~chet/
OpenPGP_signature.asc (application/pgp-signature, 203 B)
-----BEGIN PGP SIGNATURE-----

wmMEABEIACMWIQR8ATX7CIqvbGbGULm7WGnwZOp0qwUCapHs2wUDAAAAAAAKCRC7WGnwZOp0q5uL
AJ9ZJDCab2jlOYtxeSXieWaupxbh2gCfQeSZPL0MUaVL0sI464wZM69kLEs=
=+VJQ
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.