CVE-2023-4911
GNU C Library Buffer Overflow Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
18Exploited in Wild
YesDecision
Descriptions
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Se descubrió un desbordamiento del búfer en el cargador dinámico ld.so de la librería GNU C mientras se procesaba la variable de entorno GLIBC_TUNABLES. Este problema podría permitir que un atacante local utilice variables de entorno GLIBC_TUNABLES manipuladas con fines malintencionados al iniciar archivos binarios con permiso SUID para ejecutar código con privilegios elevados.
Dubbed Looney Tunables, Qualys discovered a buffer overflow vulnerability in the glibc dynamic loader's processing of the GLIBC_TUNABLES environment variable. This vulnerability was introduced in April 2021 (glibc 2.34) by commit 2ed18c.
GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-09-12 CVE Reserved
- 2023-10-03 CVE Published
- 2023-10-04 First Exploit
- 2023-11-21 Exploited in Wild
- 2023-12-12 KEV Due Date
- 2024-09-16 CVE Updated
- 2024-11-16 EPSS Updated
CWE
- CWE-122: Heap-based Buffer Overflow
- CWE-787: Out-of-bounds Write
CAPEC
References (40)
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2023/10/03/3 | 2024-02-22 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2238352 | 2024-01-03 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2023:5453 | 2024-02-22 | |
https://access.redhat.com/errata/RHSA-2023:5454 | 2024-02-22 | |
https://access.redhat.com/errata/RHSA-2023:5455 | 2024-02-22 | |
https://access.redhat.com/errata/RHSA-2023:5476 | 2024-02-22 | |
https://access.redhat.com/errata/RHSA-2024:0033 | 2024-02-22 | |
https://access.redhat.com/security/cve/CVE-2023-4911 | 2024-01-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | >= 2.34 < 2.39 Search vendor "Gnu" for product "Glibc" and version " >= 2.34 < 2.39" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 37 Search vendor "Fedoraproject" for product "Fedora" and version "37" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 38 Search vendor "Fedoraproject" for product "Fedora" and version "38" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 39 Search vendor "Fedoraproject" for product "Fedora" and version "39" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Codeready Linux Builder Eus Search vendor "Redhat" for product "Codeready Linux Builder Eus" | 8.6 Search vendor "Redhat" for product "Codeready Linux Builder Eus" and version "8.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Codeready Linux Builder For Arm64 Eus Search vendor "Redhat" for product "Codeready Linux Builder For Arm64 Eus" | 8.6 Search vendor "Redhat" for product "Codeready Linux Builder For Arm64 Eus" and version "8.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Codeready Linux Builder For Ibm Z Systems Eus Search vendor "Redhat" for product "Codeready Linux Builder For Ibm Z Systems Eus" | 8.6 Search vendor "Redhat" for product "Codeready Linux Builder For Ibm Z Systems Eus" and version "8.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Codeready Linux Builder For Power Little Endian Eus Search vendor "Redhat" for product "Codeready Linux Builder For Power Little Endian Eus" | 8.6 Search vendor "Redhat" for product "Codeready Linux Builder For Power Little Endian Eus" and version "8.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Virtualization Search vendor "Redhat" for product "Virtualization" | 4.0 Search vendor "Redhat" for product "Virtualization" and version "4.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Virtualization Host Search vendor "Redhat" for product "Virtualization Host" | 4.0 Search vendor "Redhat" for product "Virtualization Host" and version "4.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 8.0 Search vendor "Redhat" for product "Enterprise Linux" and version "8.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 9.0 Search vendor "Redhat" for product "Enterprise Linux" and version "9.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Eus Search vendor "Redhat" for product "Enterprise Linux Eus" | 8.6 Search vendor "Redhat" for product "Enterprise Linux Eus" and version "8.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux For Arm 64 Eus Search vendor "Redhat" for product "Enterprise Linux For Arm 64 Eus" | 8.6_aarch64 Search vendor "Redhat" for product "Enterprise Linux For Arm 64 Eus" and version "8.6_aarch64" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux For Ibm Z Systems Eus S390x Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems Eus S390x" | 8.6 Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems Eus S390x" and version "8.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux For Power Big Endian Eus Search vendor "Redhat" for product "Enterprise Linux For Power Big Endian Eus" | 8.6_ppc64le Search vendor "Redhat" for product "Enterprise Linux For Power Big Endian Eus" and version "8.6_ppc64le" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Aus Search vendor "Redhat" for product "Enterprise Linux Server Aus" | 8.6 Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "8.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Tus Search vendor "Redhat" for product "Enterprise Linux Server Tus" | 8.6 Search vendor "Redhat" for product "Enterprise Linux Server Tus" and version "8.6" | - |
Affected
|