Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56389

Опубликовано: 29 июл. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

A flaw was found in GNU Bison. During HTML report generation, the software improperly handles grammar-defined configuration variables. An attacker can provide a specially crafted grammar file that overrides the executable used for XML-to-HTML transformation. This allows for the execution of an arbitrary program with the privileges of the Bison process, leading to arbitrary code execution.

Отчет

This is a Moderate arbitrary code execution flaw in GNU Bison. The vulnerability arises when the bison --html command processes a specially crafted grammar file, enabling an attacker to define and execute an arbitrary program with the privileges of the Bison process. Exploitation requires user interaction to process a malicious grammar file, which limits the attack surface to scenarios where untrusted input is explicitly processed.

Меры по смягчению последствий

To mitigate this vulnerability, avoid processing untrusted or unverified grammar files with the bison --html command. Restrict the use of bison --html to trusted input sources only. This operational control reduces the risk of arbitrary code execution by preventing the vulnerable code path from being triggered with malicious input.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bisonFix deferred
Red Hat Enterprise Linux 6bisonOut of support scope
Red Hat Enterprise Linux 7bisonFix deferred
Red Hat Enterprise Linux 8bisonFix deferred
Red Hat Enterprise Linux 9bisonFix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Not affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2508369bison: GNU Bison: Arbitrary Code Execution via malicious grammar file

EPSS

Процентиль: 5%
0.00158
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 2 месяцев назад

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

CVSS3: 8.6
nvd
около 2 месяцев назад

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

msrc
около 2 месяцев назад

Arbitrary Command Execution in GNU Bison

CVSS3: 8.6
debian
около 2 месяцев назад

GNU Bison allows for an execution of an arbitrary program during HTML ...

CVSS3: 8.6
github
около 2 месяцев назад

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

EPSS

Процентиль: 5%
0.00158
Низкий

5.5 Medium

CVSS3