CVE-2023-4911
Glibc: buffer overflow in ld.so leading to privilege escalation
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- September 12, 2023
- Published Date
- October 03, 2023
- Last Updated
- January 28, 2025
- Vendor
- , Red Hat
- Product
- , Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0 Extended Update Support, Red Hat Virtualization 4 for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7
- Description
- A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
- Tags
- Exploitation
- Active
- Technical Impact
- Total
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
SSVC Information
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2023-11-21 00:00:00 UTC |
Recent Mentions
Siemens SIMATIC S7-1500 CPU Family
Source: All CISA Advisories • Published: 2025-06-12 12:00:00 UTC
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/glibc_tunables_priv_esc.rb | 2025-04-29 11:01:17 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
glibc_tunables_priv_esc
Type: metasploit • Created: Unknown
NishanthAnand21/CVE-2023-4911-PoC
Type: github • Created: 2024-01-20 18:47:07 UTC • Stars: 2
yanfernandess/Looney-Tunables-CVE-2023-4911
Type: github • Created: 2024-01-19 18:20:05 UTC • Stars: 2
Diego-AltF4/CVE-2023-4911
Type: github • Created: 2023-10-28 20:05:30 UTC • Stars: 8
KernelKrise/CVE-2023-4911
Type: github • Created: 2023-10-25 11:59:34 UTC • Stars: 11
ruycr4ft/CVE-2023-4911
Type: github • Created: 2023-10-11 14:49:22 UTC • Stars: 16
hadrian3689/looney-tunables-CVE-2023-4911
Type: github • Created: 2023-10-10 22:04:23 UTC • Stars: 27
xiaoQ1z/CVE-2023-4911
Type: github • Created: 2023-10-08 03:26:24 UTC • Stars: 1
RickdeJager/CVE-2023-4911
Type: github • Created: 2023-10-04 14:32:49 UTC • Stars: 168
leesh3288/CVE-2023-4911
Type: github • Created: 2023-10-04 14:12:16 UTC • Stars: 385
Green-Avocado/CVE-2023-4911
Type: github • Created: 2023-10-04 11:58:58 UTC • Stars: 14
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Proof of Concept Exploit Available
-
Detected by Metasploit