I am releasing here the source RPMs for the patched bash to address CVE-2014-7169 and CVE-2014-6271.
These are released under the GNU public licence. The patches I have copied or created are derived from RHEL source RPMs for RHEL 5 also released under the GNU public licence. These patches are included in the SRPM file in the normal way.
The patch for CVE-2014-6271 is unchanged from that for RHEL5. The patch for CVE-2014-7169 required a minor change. This change has not been verified for correct operation. Caveat emptor.
Andrew Daviel advax[at]triumf.ca October 2014