CVE-2026-85013
A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.
वीकनेस
A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.
संदर्भ
- https://access.redhat.com/errata/RHSA-2026:64766
- https://access.redhat.com/security/cve/CVE-2026-85013
- https://bugzilla.redhat.com/show_bug.cgi?id=2465635
- https://github.com/envmodules/modules/security/advisories/GHSA-8hrw-p88g-qhmg
- https://github.com/envmodules/modules/security/advisories/GHSA-8hrw-p88g-qhmg
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।