PT-2023-5614 · Gnu+7 · Glibc+7

·

CVE-2023-4911

·

Published

2023-10-03

·

Updated

2026-09-02

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNU C Library versions 2.34 and later
Description A buffer overflow exists in the dynamic loader ld.so of the GNU C Library (glibc) when processing the GLIBC TUNABLES environment variable. A local attacker can exploit this by using maliciously crafted GLIBC TUNABLES variables when launching binaries with SUID permissions to execute arbitrary code with elevated privileges, potentially gaining root access. The issue was introduced in April 2021 with the release of glibc version 2.34.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

DoS

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:5453
ALSA-2023:5455
ALSA-2023_5453
ALSA-2023_5455
ALT-PU-2023-6087
ALT-PU-2023-6088
ALT-PU-2023-6180
AZL-31117
AZL-34733
BDU:2023-06269
CESA-2023_5455
CVE-2023-4911
DSA-5514-1
ELSA-2023-12850
ELSA-2023-12851
ELSA-2023-5453
ELSA-2023-5455
MGASA-2023-0286
OESA-2023-1723
OESA-2023-1724
OESA-2023-1725
OPENSUSE-SU-2024:13294-1
RHSA-2023:5453
RHSA-2023:5454
RHSA-2023:5455
RHSA-2023:5476
RHSA-2023_5453
RHSA-2023_5455
RHSA-2024:0033
RLSA-2023:5455
RLSA-2023_5455
ROSA-SA-2024-2331
USN-6409-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Ubuntu
Glibc