CVE-2023-4911
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBCTUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBCTUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?fieldcve=CVE-2023-4911, https://access.redhat.com/errata/RHSA-2023:5453, https://access.redhat.com/errata/RHSA-2023:5454, https://access.redhat.com/errata/RHSA-2023:5455, https://access.redhat.com/errata/RHSA-2023:5476, https://access.redhat.com/errata/RHSA-2024:0033, https://access.redhat.com/security/cve/CVE-2023-4911, https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt, https://www.qualys.com/cve-2023-4911/, http://packetstormsecurity.com/files/174986/glibc-ld.so-Local-Privilege-Escalation.html, http://packetstormsecurity.com/files/176288/Glibc-Tunables-Privilege-Escalation.html, http://seclists.org/fulldisclosure/2023/Oct/11, https://security.gentoo.org/glsa/202310-03, https://security.netapp.com/advisory/ntap-20231013-0006/, https://bugzilla.redhat.com/showbug.cgi?id=2238352, http://www.openwall.com/lists/oss-security/2023/10/03/2, http://www.openwall.com/lists/oss-security/2023/10/03/3, http://www.openwall.com/lists/oss-security/2023/10/05/1, http://www.openwall.com/lists/oss-security/2023/10/13/11, http://www.openwall.com/lists/oss-security/2023/10/14/3, http://www.openwall.com/lists/oss-security/2023/10/14/5, http://www.openwall.com/lists/oss-security/2023/10/14/6, https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/, https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/, https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/, https://www.debian.org/security/2023/dsa-5514
