A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
|
History
06 Nov 2025, 14:50
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4911 - US Government Resource |
Information
Published : 2023-10-03 18:15
Updated : 2025-11-06 14:50
NVD link : CVE-2023-4911
Mitre link : CVE-2023-4911
CVE.ORG link : CVE-2023-4911
JSON object : View
Products Affected
redhat
- codeready_linux_builder_eus
- enterprise_linux
- virtualization
- codeready_linux_builder_for_arm64
- codeready_linux_builder_for_power_little_endian
- enterprise_linux_eus
- enterprise_linux_for_power_little_endian
- enterprise_linux_for_arm_64
- codeready_linux_builder_for_arm64_eus
- enterprise_linux_for_arm_64_eus
- codeready_linux_builder_for_power_little_endian_eus
- codeready_linux_builder
- codeready_linux_builder_for_ibm_z_systems_eus
- enterprise_linux_for_ibm_z_systems_eus_s390x
- enterprise_linux_server_tus
- virtualization_host
- enterprise_linux_for_power_little_endian_eus
- enterprise_linux_for_power_big_endian_eus
- enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
- enterprise_linux_for_ibm_z_systems_eus
- enterprise_linux_server_aus
- codeready_linux_builder_for_ibm_z_systems
- enterprise_linux_for_ibm_z_systems
netapp
- ontap_select_deploy_administration_utility
- h700s_firmware
- h410s
- h410c
- h500s
- h410s_firmware
- h300s
- h410c_firmware
- h300s_firmware
- h700s
- h500s_firmware
canonical
- ubuntu_linux
debian
- debian_linux
gnu
- glibc
fedoraproject
- fedora
