« List of all CVEs

CVE-2023-4911

Glibc: buffer overflow in ld.so leading to privilege escalation

Published: 10/3/2023 Last updated: 11/20/2025 Reserved: 9/12/2023

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 7.8 High CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Opam packages affected (1)

gettext-stub

Products affected (27)

Product Vendor Version
Red Hat Enterprise Linux 7 Red Hat SG8275P
Red Hat Enterprise Linux 7 Red Hat Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below
Red Hat Enterprise Linux 8 Red Hat <= 6.5.19
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat 6.0.1.3
Red Hat Enterprise Linux 9 Red Hat SD888
Red Hat Enterprise Linux 9 Red Hat n/a
Red Hat Enterprise Linux 9 Red Hat 6.1.0.0
Red Hat Enterprise Linux 9 Red Hat SDX55
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat n/a
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Red Hat SDX65M
Red Hat Enterprise Linux 6 Red Hat 6.0.1.2
Red Hat Enterprise Linux 7 Red Hat n/a
Red Hat Enterprise Linux 8 Red Hat SD855
Red Hat Enterprise Linux 9 Red Hat n/a
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat QCA6431
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Red Hat <= 2.3.12
SD835
Red Hat Enterprise Linux 7 Red Hat 6.0.1.4
Red Hat Enterprise Linux 8 Red Hat < 88
Red Hat Enterprise Linux 8 Red Hat 10.0.1.371
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat QCA6426
Red Hat Enterprise Linux 9 Red Hat QCA6430
Red Hat Enterprise Linux 9 Red Hat n/a
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Red Hat QCA6436
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Red Hat 6.0.1.5
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Red Hat SG4150P
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Red Hat n/a

References (72)

Credits (2)