Which vulnerability in GNU Bash was publicly disclosed in 2014?

The story behind the answer

The GNU Bash vulnerability publicly disclosed in 2014 was called Shellshock.

Shellshock involved Bash's handling of specially crafted environment variables containing function definitions. In vulnerable versions, attackers could append commands that Bash executed when processing the variable. This created risks for web servers, scripts, DHCP clients, and other systems that passed external data into shell environments.

The first major Shellshock vulnerability was tracked as CVE-2014-6271, though related flaws received additional identifiers. It was compared with Heartbleed because both received extensive media attention, but they affected different software and worked in different ways: Heartbleed exposed memory from OpenSSL, while Shellshock involved command execution through Bash.

Bash is a command-line shell widely used on Unix-like operating systems. Patches and updated packages were released quickly, but the incident showed how a small component used deep inside common software could create broad security exposure.

Source: Wikipedia · fact-checked Sept. 2026

Add question to a list

Choose a list to keep this question in: