CVE-2023-4911

high KEV
Published 2023-10-05 ยท Modified 2023-11-21
CVSS v3
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
10.0

Description

GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges.

CISA KEV

Vendor
GNU
Product
GNU C Library
Due date
2023-12-12

Predictions

Exploit likelihood
99%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27
{Vendor advisory: cisa-kev โ€” This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa, https://access.redhat.com/security/cve/cve-2023-4911, https://www.debian.org/security/2023/dsa-5514 ; https://nvd.nist.gov/vuln/detail/CVE-2023-4911 }

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description glibc: buffer overflow in ld.so leading to privilege escalation Red Hat statement This vulnerability was introduced in glibc version 2.34. RHEL-8 ships glibc 2.28, which is not originally affected by this vulnerability. However, the commit that introduced this vulnerability was backported to RHEL-8.5, making this version and onward vulnerable. RHEL-8.4 and older are not affected byโ€ฆ

Description

glibc: buffer overflow in ld.so leading to privilege escalation

Red Hat statement

This vulnerability was introduced in glibc version 2.34. RHEL-8 ships glibc 2.28, which is not originally affected by this vulnerability. However, the commit that introduced this vulnerability was backported to RHEL-8.5, making this version and onward vulnerable. RHEL-8.4 and older are not affected by this vulnerability.

CVSS v3: 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8glibc-0:2.28-225.el8_8.6RHSA-2023:54552023-10-05T00:00:00Z
Red Hat Enterprise Linux 8glibc-0:2.28-225.el8_8.6RHSA-2023:54552023-10-05T00:00:00Z
Red Hat Enterprise Linux 8.6 Extended Update Supportglibc-0:2.28-189.6.el8_6RHSA-2023:54762023-10-05T00:00:00Z
Red Hat Enterprise Linux 9glibc-0:2.34-60.el9_2.7RHSA-2023:54532023-10-05T00:00:00Z
Red Hat Enterprise Linux 9glibc-0:2.34-60.el9_2.7RHSA-2023:54532023-10-05T00:00:00Z
Red Hat Enterprise Linux 9.0 Extended Update Supportglibc-0:2.34-28.el9_0.4RHSA-2023:54542023-10-05T00:00:00Z
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8glibc-0:2.28-189.6.el8_6RHSA-2023:54762023-10-05T00:00:00Z
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8redhat-release-virtualization-host-0:4.5.3-10.el8evRHSA-2024:00332024-01-03T00:00:00Z
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8redhat-virtualization-host-0:4.5.3-202312060823_8.6RHSA-2024:00332024-01-03T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6glibcNot affected
Red Hat Enterprise Linux 7compat-glibcNot affected
Red Hat Enterprise Linux 7glibcNot affected

Apply commands

bash fix
Apply RHSA-2023:5455 for Red Hat Enterprise Linux 8
yum update -y glibc
# or:
dnf upgrade -y glibc

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Not affected
redhatRed Hat Enterprise Linux 7Not affected
redhatRed Hat Enterprise Linux 7Not affected

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-52479 local linux
Beatriz Fresno Naumova ยท 2026-02-11

glibc 2.38 - Buffer Overflow

Source code queued for fetch โ€” refresh in a moment.

Metasploit modules

Glibc Tunables Privilege Escalation CVE-2023-4911 (aka Looney Tunables)
Source fetch failed: fetch_error โ€” view the original via the link above.

OS impact

fedora Fedora Affected 3 releases
VersionStatusFixed in
39 Affected โ€”
38 Affected โ€”
37 Affected โ€”
suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
ubuntu Ubuntu Affected 2 releases
VersionStatusFixed in
23.04 Affected โ€”
22.04 Affected โ€”
debian Debian Mixed 7 releases
VersionStatusFixed in
trixie Fixed 2.37-12
sid Fixed 2.37-12
forky Fixed 2.37-12
bullseye Fixed 2.31-13+deb11u7
bookworm Fixed 2.36-9+deb12u3
12.0 Affected โ€”
11.0 Affected โ€”
redhat Red Hat Mixed 9 releases
VersionStatusFixed in
9.6 Affected โ€”
9.4 Affected โ€”
9.2 Affected โ€”
9.0_aarch64 Affected โ€”
9.0 Affected โ€”
9 Fixed โ€”
8.6 Affected โ€”
8.0 Affected โ€”
8 Fixed โ€”
almalinux AlmaLinux Fixed 2 releases
VersionStatusFixed in
9 Fixed glibc-locale-source-2.34-60.el9_2.7.aarch64.rpm
8 Fixed glibc-doc-2.28-225.el8_8.6.noarch.rpm
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed โ€”

Application impact

References

CWEs

CWE-122 CWE-787

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.