PT-2023-5614 · Gnu+7 · Glibc+7
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GNU C Library versions 2.34 and later
Description
A buffer overflow exists in the dynamic loader
ld.so of the GNU C Library (glibc) when processing the GLIBC TUNABLES environment variable. A local attacker can exploit this by using maliciously crafted GLIBC TUNABLES variables when launching binaries with SUID permissions to execute arbitrary code with elevated privileges, potentially gaining root access. The issue was introduced in April 2021 with the release of glibc version 2.34.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
DoS
Memory Corruption
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Ubuntu
Glibc