Untriaged
Permalink
CVE-2023-4911
7.8 HIGH
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Glibc: buffer overflow in ld.so leading to privilege escalation
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
References
-
-
-
-
-
-
-
-
http://seclists.org/fulldisclosure/2023/Oct/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/2 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/05/1 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/13/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/5 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/6 x_transferred
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202310-03 x_transferred
-
https://security.netapp.com/advisory/ntap-20231013-0006/ x_transferred
-
https://www.debian.org/security/2023/dsa-5514 x_transferred
-
https://www.qualys.com/cve-2023-4911/ x_transferred
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
http://seclists.org/fulldisclosure/2023/Oct/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/2 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/05/1 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/13/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/5 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/6 x_transferred
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202310-03 x_transferred
-
https://security.netapp.com/advisory/ntap-20231013-0006/ x_transferred
-
https://www.debian.org/security/2023/dsa-5514 x_transferred
-
https://www.qualys.com/cve-2023-4911/ x_transferred
-
-
-
-
-
-
-
-
http://seclists.org/fulldisclosure/2023/Oct/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/2 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/05/1 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/13/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/5 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/6 x_transferred
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202310-03 x_transferred
-
https://security.netapp.com/advisory/ntap-20231013-0006/ x_transferred
-
https://www.debian.org/security/2023/dsa-5514 x_transferred
-
https://www.qualys.com/cve-2023-4911/ x_transferred
-
-
-
-
-
-
-
-
http://seclists.org/fulldisclosure/2023/Oct/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/2 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/05/1 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/13/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/5 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/6 x_transferred
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202310-03 x_transferred
-
https://security.netapp.com/advisory/ntap-20231013-0006/ x_transferred
-
https://www.debian.org/security/2023/dsa-5514 x_transferred
-
https://www.qualys.com/cve-2023-4911/ x_transferred
-
-
-
-
-
-
-
-
http://seclists.org/fulldisclosure/2023/Oct/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/2 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/05/1 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/13/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/5 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/6 x_transferred
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202310-03 x_transferred
-
https://security.netapp.com/advisory/ntap-20231013-0006/ x_transferred
-
https://www.debian.org/security/2023/dsa-5514 x_transferred
-
https://www.qualys.com/cve-2023-4911/ x_transferred
-
-
-
-
-
-
-
-
http://seclists.org/fulldisclosure/2023/Oct/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/2 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/05/1 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/13/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/5 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/6 x_transferred
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202310-03 x_transferred
-
https://security.netapp.com/advisory/ntap-20231013-0006/ x_transferred
-
https://www.debian.org/security/2023/dsa-5514 x_transferred
-
https://www.qualys.com/cve-2023-4911/ x_transferred
-
-
-
-
-
-
-
-
-
http://seclists.org/fulldisclosure/2023/Oct/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/2 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/05/1 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/13/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/5 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/6 x_transferred
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202310-03 x_transferred
-
https://security.netapp.com/advisory/ntap-20231013-0006/ x_transferred
-
https://www.debian.org/security/2023/dsa-5514 x_transferred
-
https://www.qualys.com/cve-2023-4911/ x_transferred
-
-
-
-
-
-
-
-
-
http://seclists.org/fulldisclosure/2023/Oct/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/2 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/05/1 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/13/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/5 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/6 x_transferred
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202310-03 x_transferred
-
https://security.netapp.com/advisory/ntap-20231013-0006/ x_transferred
-
https://www.debian.org/security/2023/dsa-5514 x_transferred
-
https://www.qualys.com/cve-2023-4911/ x_transferred
-
-
-
-
-
-
-
-
-
http://seclists.org/fulldisclosure/2023/Oct/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/2 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/05/1 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/13/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/5 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/6 x_transferred
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202310-03 x_transferred
-
https://security.netapp.com/advisory/ntap-20231013-0006/ x_transferred
-
https://www.debian.org/security/2023/dsa-5514 x_transferred
-
https://www.qualys.com/cve-2023-4911/ x_transferred
-
-
-
-
-
-
-
-
-
http://seclists.org/fulldisclosure/2023/Oct/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/2 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/05/1 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/13/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/5 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/6 x_transferred
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202310-03 x_transferred
-
https://security.netapp.com/advisory/ntap-20231013-0006/ x_transferred
-
https://www.debian.org/security/2023/dsa-5514 x_transferred
-
https://www.qualys.com/cve-2023-4911/ x_transferred
-
-
-
-
-
-
-
-
-
http://seclists.org/fulldisclosure/2023/Oct/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/2 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/05/1 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/13/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/5 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/6 x_transferred
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202310-03 x_transferred
-
https://security.netapp.com/advisory/ntap-20231013-0006/ x_transferred
-
https://www.debian.org/security/2023/dsa-5514 x_transferred
-
https://www.qualys.com/cve-2023-4911/ x_transferred
-
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023… government-resource
-
-
-
-
-
-
-
-
-
http://seclists.org/fulldisclosure/2023/Oct/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/2 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/05/1 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/13/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/5 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/6 x_transferred
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202310-03 x_transferred
-
https://security.netapp.com/advisory/ntap-20231013-0006/ x_transferred
-
https://www.debian.org/security/2023/dsa-5514 x_transferred
-
https://www.qualys.com/cve-2023-4911/ x_transferred
-
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023… government-resource
-
-
-
-
-
-
-
-
http://seclists.org/fulldisclosure/2023/Oct/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/2 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/05/1 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/13/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/5 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/6 x_transferred
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202310-03 x_transferred
-
https://security.netapp.com/advisory/ntap-20231013-0006/ x_transferred
-
https://www.debian.org/security/2023/dsa-5514 x_transferred
-
https://www.qualys.com/cve-2023-4911/ x_transferred
-
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023… government-resource
-
-
-
-
-
-
-
-
http://seclists.org/fulldisclosure/2023/Oct/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/2 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/05/1 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/13/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/5 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/6 x_transferred
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202310-03 x_transferred
-
https://security.netapp.com/advisory/ntap-20231013-0006/ x_transferred
-
https://www.debian.org/security/2023/dsa-5514 x_transferred
-
https://www.qualys.com/cve-2023-4911/ x_transferred
-
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023… government-resource
-
-
-
-
-
-
-
-
http://seclists.org/fulldisclosure/2023/Oct/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/2 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/03/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/05/1 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/13/11 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/3 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/5 x_transferred
-
http://www.openwall.com/lists/oss-security/2023/10/14/6 x_transferred
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202310-03 x_transferred
-
https://security.netapp.com/advisory/ntap-20231013-0006/ x_transferred
-
https://www.debian.org/security/2023/dsa-5514 x_transferred
-
https://www.qualys.com/cve-2023-4911/ x_transferred
-
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023… government-resource
Affected products
glibc
- <2.39
- *
compat-glibc
redhat-virtualization-host
- *
redhat-release-virtualization-host
- *
Matching in nixpkgs
pkgs.glibc
GNU C Library
pkgs.mtrace
Perl script used to interpret and provide human readable output of the trace log contained in the file mtracedata, whose contents were produced by mtrace(3)
pkgs.glibcInfo
GNU Info manual of the GNU C Library
pkgs.glibc_multi
None
pkgs.glibcLocales
Locale information for the GNU C Library
pkgs.glibc_memusage
GNU C Library
pkgs.glibcLocalesUtf8
Locale information for the GNU C Library
pkgs.unixtools.getent
None
pkgs.unixtools.locale
None
pkgs.unixtools.getconf
None
Package maintainers
-
@Ma27 Maximilian Bosch <maximilian@mbosch.me>
-
@ConnorBaker Connor Baker <ConnorBaker01@gmail.com>