7.8
CVE-2023-4911
- EPSS 81.42%
- Veröffentlicht 03.10.2023 18:15:10
- Zuletzt bearbeitet 12.05.2026 16:24:45
- Erkennungen
Glibc: buffer overflow in ld.so leading to privilege escalation
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netapp ≫ Bootstrap Os Version -
Siemens ≫ Simatic S7-1500 Tm Mfp Firmware Version < 1.1
Fedoraproject ≫ Fedora Version 37
Fedoraproject ≫ Fedora Version 38
Fedoraproject ≫ Fedora Version 39
Redhat ≫ Codeready Linux Builder Version 9.0
Redhat ≫ Codeready Linux Builder Eus Version 8.6
Redhat ≫ Codeready Linux Builder Eus Version 9.2
Redhat ≫ Codeready Linux Builder Eus Version 9.4
Redhat ≫ Codeready Linux Builder Eus Version 9.6
Redhat ≫ Codeready Linux Builder For Arm64 Version 9.0_aarch64
Redhat ≫ Codeready Linux Builder For Arm64 Eus Version 8.6
Redhat ≫ Codeready Linux Builder For Arm64 Eus Version 9.2_aarch64
Redhat ≫ Codeready Linux Builder For Arm64 Eus Version 9.4_aarch64
Redhat ≫ Codeready Linux Builder For Arm64 Eus Version 9.6_aarch64
Redhat ≫ Codeready Linux Builder For Ibm Z Systems Version 9.0_s390x
Redhat ≫ Codeready Linux Builder For Ibm Z Systems Eus Version 8.6
Redhat ≫ Codeready Linux Builder For Ibm Z Systems Eus Version 9.2_s390x
Redhat ≫ Codeready Linux Builder For Ibm Z Systems Eus Version 9.4_s390x
Redhat ≫ Codeready Linux Builder For Ibm Z Systems Eus Version 9.6_s390x
Redhat ≫ Codeready Linux Builder For Power Little Endian Version 9.0_ppc64le
Redhat ≫ Codeready Linux Builder For Power Little Endian Eus Version 8.6
Redhat ≫ Codeready Linux Builder For Power Little Endian Eus Version 9.2_ppc64le
Redhat ≫ Codeready Linux Builder For Power Little Endian Eus Version 9.4_ppc64le
Redhat ≫ Codeready Linux Builder For Power Little Endian Eus Version 9.6_ppc64le
Redhat ≫ Virtualization Version 4.0
Redhat ≫ Virtualization Host Version 4.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Eus Version 8.6
Redhat ≫ Enterprise Linux Eus Version 9.2
Redhat ≫ Enterprise Linux Eus Version 9.4
Redhat ≫ Enterprise Linux Eus Version 9.6
Redhat ≫ Enterprise Linux For Arm 64 Version 9.0_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 8.6_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 9.2_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 9.4_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 9.6_aarch64
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 9.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 9.2_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 9.4_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 9.6_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus S390x Version 8.6
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 8.6_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Version 9.0_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 9.2_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 9.4_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 9.6_ppc64le
Redhat ≫ Enterprise Linux Server Aus Version 8.6
Redhat ≫ Enterprise Linux Server Aus Version 9.2
Redhat ≫ Enterprise Linux Server Aus Version 9.4
Redhat ≫ Enterprise Linux Server Aus Version 9.6
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 9.2_ppc64le
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 9.4_ppc64le
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 9.6_ppc64le
Redhat ≫ Enterprise Linux Server Tus Version 8.6
Redhat ≫ Enterprise Linux Update Services For Sap Solutions Version 9.2
Redhat ≫ Enterprise Linux Update Services For Sap Solutions Version 9.4
Redhat ≫ Enterprise Linux Update Services For Sap Solutions Version 9.6
Canonical ≫ Ubuntu Linux Version 22.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 23.04
Debian ≫ Debian Linux Version 11.0
Debian ≫ Debian Linux Version 12.0
Netapp ≫ H410c Firmware Version -
Netapp ≫ H300s Firmware Version -
Netapp ≫ H500s Firmware Version -
Netapp ≫ H700s Firmware Version -
Netapp ≫ H410s Firmware Version -
Netapp ≫ Ontap Select Deploy Administration Utility Version -
21.11.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog
GNU C Library Buffer Overflow Vulnerability
SchwachstelleGNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges.
BeschreibungApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 81.42% | 0.996 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| RedHat | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-122 Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
http://packetstormsecurity.com/files/174986/glibc-ld.so-Local-Privilege-Escalation.html
http://seclists.org/fulldisclosure/2023/Oct/11
http://www.openwall.com/lists/oss-security/2023/10/03/2
https://security.gentoo.org/glsa/202310-03
https://access.redhat.com/errata/RHSA-2023:5453
https://access.redhat.com/errata/RHSA-2023:5455
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/
https://access.redhat.com/errata/RHSA-2023:5454
https://access.redhat.com/errata/RHSA-2023:5476
https://access.redhat.com/errata/RHSA-2024:0033
https://access.redhat.com/security/cve/CVE-2023-4911
https://bugzilla.redhat.com/show_bug.cgi?id=2238352
https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
https://www.qualys.com/cve-2023-4911/
http://packetstormsecurity.com/files/176288/Glibc-Tunables-Privilege-Escalation.html
http://www.openwall.com/lists/oss-security/2023/10/03/3
http://www.openwall.com/lists/oss-security/2023/10/05/1
http://www.openwall.com/lists/oss-security/2023/10/13/11
http://www.openwall.com/lists/oss-security/2023/10/14/3
http://www.openwall.com/lists/oss-security/2023/10/14/5
http://www.openwall.com/lists/oss-security/2023/10/14/6
https://security.netapp.com/advisory/ntap-20231013-0006/
https://www.debian.org/security/2023/dsa-5514
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4911
https://www.exploit-db.com/exploits/52479
https://cert-portal.siemens.com/productcert/html/ssa-082556.html
https://cert-portal.siemens.com/productcert/html/ssa-831302.html
https://cert-portal.siemens.com/productcert/html/ssa-794697.html