CVE-2023-4911 KEV EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 81.4% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2023-12-12.
Description
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 81.42% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-122 |
| On CISA KEV | yes — remediate by 2023-12-12 |
| Public exploit | yes |
| Published | 2023-10-03 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | GNU C Library Buffer Overflow Vulnerability |
|---|---|
| Added | 2023-11-21 |
| Due | 2023-12-12 |
| Vendor / product | GNU / GNU C Library |
| Ransomware use | none reported |
Affected (40)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| debian | debian linux |
| fedoraproject | fedora |
| gnu | glibc |
| netapp | bootstrap os |
| netapp | h410c |
| netapp | h410c firmware |
| netapp | hci compute node |
| redhat | codeready linux builder |
| redhat | codeready linux builder eus |
| redhat | codeready linux builder for arm64 |
| redhat | codeready linux builder for arm64 eus |
| redhat | codeready linux builder for ibm z systems |
| redhat | codeready linux builder for ibm z systems eus |
| redhat | codeready linux builder for power little endian |
| redhat | codeready linux builder for power little endian eus |
| redhat | enterprise linux |
| redhat | enterprise linux eus |
| redhat | enterprise linux for arm 64 |
| redhat | enterprise linux for arm 64 eus |
| redhat | enterprise linux for ibm z systems |
| redhat | enterprise linux for ibm z systems eus |
| redhat | enterprise linux for ibm z systems eus s390x |
| redhat | enterprise linux for power big endian eus |
| redhat | enterprise linux for power little endian |
| redhat | enterprise linux for power little endian eus |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server for power little endian update services for sap solutions |
| redhat | enterprise linux server tus |
| redhat | enterprise linux update services for sap solutions |
| redhat | virtualization |
| redhat | virtualization host |
| siemens | simatic s7-1500 cpu 1518-4 pn\/dp mfp |
| siemens | simatic s7-1500 cpu 1518-4 pn\/dp mfp firmware |
| siemens | simatic s7-1500 cpu 1518f-4 pn\/dp mfp |
| siemens | simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware |
| siemens | simatic s7-1500 tm mfp |
| siemens | simatic s7-1500 tm mfp firmware |
| siemens | siplus s7-1500 cpu 1518-4 pn\/dp mfp |
| siemens | siplus s7-1500 cpu 1518-4 pn\/dp mfp firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | glibc 2.38 - Buffer Overflow | 2026-02-11 |
References
- https://access.redhat.com/errata/RHSA-2023:5453
- https://access.redhat.com/errata/RHSA-2023:5454
- https://access.redhat.com/errata/RHSA-2023:5455
- https://access.redhat.com/errata/RHSA-2023:5476
- https://access.redhat.com/errata/RHSA-2024:0033
- https://access.redhat.com/security/cve/CVE-2023-4911
- https://bugzilla.redhat.com/show_bug.cgi?id=2238352
- https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
- https://www.qualys.com/cve-2023-4911/
- http://packetstormsecurity.com/files/174986/glibc-ld.so-Local-Privilege-Escalation.html
- http://packetstormsecurity.com/files/176288/Glibc-Tunables-Privilege-Escalation.html
- http://seclists.org/fulldisclosure/2023/Oct/11
- http://www.openwall.com/lists/oss-security/2023/10/03/2
- http://www.openwall.com/lists/oss-security/2023/10/03/3
- http://www.openwall.com/lists/oss-security/2023/10/05/1
- http://www.openwall.com/lists/oss-security/2023/10/13/11
- http://www.openwall.com/lists/oss-security/2023/10/14/3
- http://www.openwall.com/lists/oss-security/2023/10/14/5
- http://www.openwall.com/lists/oss-security/2023/10/14/6
- https://access.redhat.com/errata/RHSA-2023:5453
→ the Explorer · watch your stack · NVD