In Bash, the popd command can be tricked to free a user supplied address, which could be used to bypass restricted shells (rsh) on some environments to cause use-after-free (CVE-2016-9401).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2017-0005.json"