---
title: "CVE-2019-18276\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2019-18276?format=md
keywords: index, follow
---

# CVE-2019-18276

Publication date 28 November 2019

Last updated 25 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2019-18276?format=md#impact-score)

Toggle side navigation

## Description

An issue was discovered in disable\_priv\_mode in shell.c in GNU Bash through
5.0 patch 11. By default, if Bash is run with its effective UID not equal
to its real UID, it will drop privileges by setting its effective UID to
its real UID. However, it does so incorrectly. On Linux and other systems
that support "saved UID" functionality, the saved UID is not dropped. An
attacker with command execution in the shell can use "enable -f" for
runtime loading of a new builtin, which can be a shared object that calls
setuid() and therefore regains privileges. However, binaries running with
an effective UID of 0 are unaffected.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2019-18276?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| bash | 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Fixed 5.0-6ubuntu1.2 |
| 19.10 eoan | Ignored end of life |
| 19.04 disco | Ignored end of life |
| 18.04 LTS bionic | Fixed 4.4.18-2ubuntu1.3 |
| 16.04 LTS xenial | Fixed 4.3-14ubuntu1.4+esm1  Ubuntu Pro |
| 14.04 LTS trusty | Fixed 4.3-7ubuntu1.8+esm2  Ubuntu Pro |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2019-18276?format=md#patch-details)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

This issue appears to only affect bash when bash is
setuid. Ubuntu does not ship with bash setuid, so this has minimal
impact for Ubuntu users. This is why we have rated the priority
for this issue 'low'.
reproducer steps in the suse bugzilla

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| bash | * Upstream:   [?h=deve](https://git.savannah.gnu.org/cgit/bash.git/commit/?h=devel&id=951bdaad7a18cc0dc1036bba86b18b90874d39ff) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.8 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.8 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18276)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-18276)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2019-18276)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2019-18276)

### Related Ubuntu Security Notices (USN)

+ [USN-5380-1](https://usn.ubuntu.com/USN-5380-1)
+ Bash vulnerability
+ 20 April 2022

### Other references

* <https://www.youtube.com/watch?v=-wGtxJ8opa8>
* <https://www.cve.org/CVERecord?id=CVE-2019-18276>
