« List of all CVEs

CVE-2023-4911

Glibc: buffer overflow in ld.so leading to privilege escalation

Published: 10/3/2023 Last updated: 4/30/2025 Reserved: 9/12/2023

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 7.8 High CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Opam packages affected (1)

gettext-stub

Products affected (15)

Product Vendor Version
Red Hat Enterprise Linux 7 Red Hat <= *
Red Hat Enterprise Linux 8 Red Hat 1.5.8
Red Hat Enterprise Linux 8 Red Hat 1.5.10
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat 22.0 ap367986
Red Hat Enterprise Linux 9 Red Hat < 16.0.5443.1000
Red Hat Enterprise Linux 9 Red Hat < publication
Red Hat Enterprise Linux 9 Red Hat 22.0 ap362532
Red Hat Enterprise Linux 9 Red Hat < 14
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat unspecified
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Red Hat < 5.8
Red Hat Enterprise Linux 7 Red Hat 1.0.0
Red Hat Enterprise Linux 6 Red Hat 0.11.0.0 to 0.11.0.2
3.7.4
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Red Hat <= 6.1.*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Red Hat < 18.5x

References (35)

Credits (1)