QID 240283

Date Published: 2022-05-11

QID 240283: Red Hat Update for zsh (RHSA-2022:2120)

the zsh shell is a command interpreter usable as an interactive login shell and as a shell script command processor.
Zsh resembles the ksh shell (the korn shell), but includes many enhancements.
Zsh supports command-line editing, built-in spelling correction, programmable command completion, shell functions (with autoloading), a history mechanism, and more.

Security Fix(es):
  • zsh: prompt expansion vulnerability (cve-2021-45444)

Affected Products:

  • Red Hat enterprise linux for x86_64 8 x86_64
  • Red Hat enterprise linux for ibm z systems 8 s390x
  • Red Hat enterprise linux for power, little endian 8 ppc64le
  • Red Hat enterprise linux for arm 64 8 aarch64



Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution
    Refer to Red Hat security advisory RHSA-2022:2120 for updates and patch information.
    Vendor References

    CVEs related to QID 240283

    Software Advisories
    Advisory ID Software Component Link
    RHSA-2022:2120 Red Hat Enterprise Linux URL Logo access.redhat.com/errata/RHSA-2022:2120