CVE-2023-4911
Confirmed PUBLISHEDGlibc: buffer overflow in ld.so leading to privilege escalation
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
- CVE Published
- Oct 03, 2023
- Exploitation Reported
- Nov 21, 2023
- CVSS
- 7.8 High
- EPSS
- 81.4%
Affected Versions
| Vendor | Product | Version | Status |
|---|---|---|---|
| Siemens |
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP
|
V3.1.5 to < * |
Affected |
| Siemens |
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP
|
V3.1.5 to < * |
Affected |
| Siemens |
SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
|
V3.1.5 to < * |
Affected |
| Siemens |
SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
|
V3.1.5 to < * |
Affected |
| Siemens |
SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
|
V3.1.5 to < * |
Affected |
| — |
—
|
2.34 to < 2.39 |
Affected |
| Red Hat |
Red Hat Enterprise Linux 8
|
0:2.28-225.el8_8.6 to < * |
Unaffected |
| Red Hat |
Red Hat Enterprise Linux 8
|
0:2.28-225.el8_8.6 to < * |
Unaffected |
| Red Hat |
Red Hat Enterprise Linux 8.6 Extended Update Support
|
0:2.28-189.6.el8_6 to < * |
Unaffected |
| Red Hat |
Red Hat Enterprise Linux 9
|
0:2.34-60.el9_2.7 to < * |
Unaffected |
| Red Hat |
Red Hat Enterprise Linux 9
|
0:2.34-60.el9_2.7 to < * |
Unaffected |
| Red Hat |
Red Hat Enterprise Linux 9.0 Extended Update Support
|
0:2.34-28.el9_0.4 to < * |
Unaffected |
| Red Hat |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
|
0:2.28-189.6.el8_6 to < * |
Unaffected |
| Red Hat |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
|
0:4.5.3-10.el8ev to < * |
Unaffected |
| Red Hat |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
|
0:4.5.3-202312060823_8.6 to < * |
Unaffected |
| Red Hat |
Red Hat Enterprise Linux 6
|
All versions (default: unaffected) |
Unaffected |
| Red Hat |
Red Hat Enterprise Linux 7
|
All versions (default: unaffected) |
Unaffected |
| Red Hat |
Red Hat Enterprise Linux 7
|
All versions (default: unaffected) |
Unaffected |
CVE References
- RHSA-2023:5453 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2023:5453
- RHSA-2023:5454 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2023:5454
- RHSA-2023:5455 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2023:5455
- RHSA-2023:5476 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2023:5476
- RHSA-2024:0033 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2024:0033
Show 4 more references
- RHBZ#2238352 bugzilla.redhat.com · Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=2238352
- VDB Entry — access.redhat.com access.redhat.com · VDB Entry https://access.redhat.com/security/cve/CVE-2023-4911
- qualys.com/2023/10/03/cve-2023-4911/looney-tunables-loc... qualys.com · CVE Record https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local...
- qualys.com/cve-2023-4911 qualys.com · CVE Record https://www.qualys.com/cve-2023-4911/
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2023-11-21 00:00 UTC |
| CVE | 2026-06-05 09:28 UTC |
Scanner Artifacts
Nuclei and Metasploit references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/glibc_tunables_priv_esc.rb | Apr 28, 2025 |
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
Exploited in the wild
Recorded 2023-11-21 00:00:00 UTC · CISA
Proof of concept available
Recorded 2023-10-04 11:58:58 UTC · GitHub
Weaknesses (CWE)
-
Heap-based Buffer Overflow
Scanner Integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/glibc_tunables_priv_esc.rb | Apr 28, 2025 |
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2024-01-20 18:47:07 UTC · 2 stars
Repository containing a Proof of Concept (PoC) demonstrating the impact of CVE-2023-4911, a vulnerability in glibc's ld.so dynamic loader, exposing risks related to Looney Tunables.
github · Created 2024-01-19 18:20:05 UTC · 2 stars
github · Created 2023-12-23 11:54:40 UTC · 0 stars
github · Created 2023-10-28 20:05:30 UTC · 8 stars
Proof of concept for CVE-2023-4911 (Looney Tunables) discovered by Qualys Threat Research Unit
github · Created 2023-10-25 11:59:34 UTC · 11 stars
Looney Tunables Local privilege escalation (CVE-2023-4911) workshop
github · Created 2023-10-10 22:04:23 UTC · 27 stars
github · Created 2023-10-08 03:26:24 UTC · 1 stars
github · Created 2023-10-04 14:32:49 UTC · 168 stars
CVE-2023-4911 proof of concept
github · Created 2023-10-04 11:58:58 UTC · 14 stars
https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
09:28 UTC about 1 month ago09:28 UTC · about 1 month ago
KEV confirmed by CVE
Exploitation attested by an external source
-
15:02 UTC about 1 year ago15:02 UTC · about 1 year ago
Metasploit module available
Exploit module available
-
00:00 UTC over 2 years ago00:00 UTC · over 2 years ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
11:58 UTC almost 3 years ago11:58 UTC · almost 3 years ago
Public PoC available
Public proof-of-concept code published
-
17:25 UTC almost 3 years ago17:25 UTC · almost 3 years ago
CVE published
Vulnerability disclosed publicly
-
13:10 UTC almost 3 years ago13:10 UTC · almost 3 years ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2023-4911
{
"cve_id": "CVE-2023-4911",
"title": "Glibc: buffer overflow in ld.so leading to privilege escalation",
"affected_vendor": ", Red Hat",
"affected_product": ", Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0 Extended Update Support, Red Hat Virtualization 4 for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 7.8,
"epss_score": 0.81422,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}