CVE-2023-4911

Confirmed PUBLISHED

Glibc: buffer overflow in ld.so leading to privilege escalation

, Red Hat · , Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0 Extended Update Support, Red Hat Virtualization 4 for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.8 High EPSS 81.4%

At a Glance

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

linux cisa metasploit
CVE Published
Oct 03, 2023
Exploitation Reported
Nov 21, 2023
CVSS
7.8 High
EPSS
81.4%
Low complexity No user interaction

Affected Versions

Vendor Product Version Status
Siemens
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP

V3.1.5 to < *

Affected
Siemens
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP

V3.1.5 to < *

Affected
Siemens
SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

V3.1.5 to < *

Affected
Siemens
SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

V3.1.5 to < *

Affected
Siemens
SIPLUS S7-1500 CPU 1518-4 PN/DP MFP

V3.1.5 to < *

Affected

glibc

2.34 to < 2.39

Affected
Red Hat
Red Hat Enterprise Linux 8

glibc

0:2.28-225.el8_8.6 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 8

glibc

0:2.28-225.el8_8.6 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 8.6 Extended Update Support

glibc

0:2.28-189.6.el8_6 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 9

glibc

0:2.34-60.el9_2.7 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 9

glibc

0:2.34-60.el9_2.7 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 9.0 Extended Update Support

glibc

0:2.34-28.el9_0.4 to < *

Unaffected
Red Hat
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8

glibc

0:2.28-189.6.el8_6 to < *

Unaffected
Red Hat
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8

redhat-release-virtualization-host

0:4.5.3-10.el8ev to < *

Unaffected
Red Hat
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8

redhat-virtualization-host

0:4.5.3-202312060823_8.6 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 6

glibc

All versions (default: unaffected)

Unaffected
Red Hat
Red Hat Enterprise Linux 7

compat-glibc

All versions (default: unaffected)

Unaffected
Red Hat
Red Hat Enterprise Linux 7

glibc

All versions (default: unaffected)

Unaffected

CVE References

  • RHSA-2023:5453 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2023:5453
  • RHSA-2023:5454 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2023:5454
  • RHSA-2023:5455 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2023:5455
  • RHSA-2023:5476 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2023:5476
  • RHSA-2024:0033 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2024:0033
Show 4 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.