A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
| Version | Score | Severity | Vector String |
|---|---|---|---|
| 3.1 | 7.8 | High | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Product | Vendor | Version |
|---|---|---|
| Red Hat Enterprise Linux 7 | Red Hat | 1.14.6 |
| <= * | ||
| Red Hat Enterprise Linux 8 | Red Hat | < 24.07.2025 |
| Red Hat Enterprise Linux 7 | Red Hat | < 1.3.9 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | Red Hat | < 5.9.0 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | Red Hat | 825.8010.00 |