Re: [SECURITY] Async-signal-unsafe operations in alrm_catcher() signal handler

Chet Ramey <[email protected]>
Newsgroups gmane.comp.shells.bash.bugs
Organization ITS, Case Western Reserve University
Message-ID <[email protected]>
On 8/27/26 9:59 PM, Collin Funk wrote:
> Sam James <[email protected]> writes:
> 
>> How is that different from just letting the process exit otherwise?
>> ~/.bash_logout will be used either way. If a process writes to arbitrary
>> bash init files, then all bets are off.
> 
> Sadly, if this reporter is determined to assign a CVE to this, I don't
> think they will run into issues. A word of caution that it is not
> worthwhile to try to resolve that if they do.

My favorite was the one where someone (not this reporter) reported a
security bug in bash that essentially consisted of:

1. Change the permissions on the shell to setuid root
2. Imagine the chaos!

They wanted a CVE, too. I don't think they got one.

Chet

-- 
``The lyf so short, the craft so long to lerne.'' - Chaucer
		 ``Ars longa, vita brevis'' - Hippocrates
Chet Ramey, UTech, CWRU    [email protected]    http://tiswww.cwru.edu/~chet/
OpenPGP_signature.asc (application/pgp-signature, 203 B)
-----BEGIN PGP SIGNATURE-----

wmMEABEIACMWIQR8ATX7CIqvbGbGULm7WGnwZOp0qwUCapHwBQUDAAAAAAAKCRC7WGnwZOp0q7K8
AJ9T6nFCU/ixAfdrExhg/ngejjBougCgn127T6skADD3YfXT7OHBcGSq/nQ=
=lrex
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.