[Lmod-announce] [SECURITY] Lmod 9.4 released (CVE-2026-85013)
A Lua based environment module system that reads TCL modulefiles.
Brought to you by:
rtmclay
|
From: Announcing n. v. of L. <lmo...@li...> - 2026-09-08 09:43:03
|
Hello All, Lmod 9.4 is released. This release fixes CVE-2026-85013 where a security vulnerability was found in the Bash completion script of the module and ml commands. This only affects bash. Other shells do not have this vulnerability. The tool compgen can cause a problem with a badly formed filename (and not the contents) can allow a local attacker to execute arbitrary commands as the victim. *Please upgrade immediately to Lmod 9.4.* *If upgrading is not immediately possible, *the fixed Bash completion script can be installed on its own, as the fix only touches this file. As an interim workaround, Bash completion for module and ml can be disabled by removing the completion script from the Bash completion directory. Special thanks to AISLE and Red Hat who found and reported this vulnerability.. Thanks also to Xavier Delaruelle for report this issue to us. Thanks also to Matthew Cawood for implementing our fix and a test. Best, Lmod Team |