CVE-2023-4911
Vulnerability Summary
Timeline
Description
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 69.92%• Percentile: 99%
Techniques & Countermeasures
- CWE-122•Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
- CWE-787•Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Affected Systems
- canonical•ubuntu_linux
22.04 | 23.04
- debian•debian_linux
11.0 | 12.0
- fedoraproject•fedora
37 | 38 | 39
- gnu•glibc
≥ 2.34, < 2.39
- netapp•bootstrap_os
na
- netapp•h300s_firmware
na
- netapp•h410c_firmware
na
- netapp•h410s_firmware
na
- netapp•h500s_firmware
na
- netapp•h700s_firmware
na
- netapp•ontap_select_deploy_administration_utility
na
- redhat•codeready_linux_builder
9.0
- redhat•codeready_linux_builder_eus
8.6 | 9.2 | 9.4 | 9.6
- redhat•codeready_linux_builder_for_arm64
9.0_aarch64
- redhat•codeready_linux_builder_for_arm64_eus
8.6 | 9.2_aarch64 | 9.4_aarch64 | 9.6_aarch64
- redhat•codeready_linux_builder_for_ibm_z_systems
9.0_s390x
- redhat•codeready_linux_builder_for_ibm_z_systems_eus
8.6 | 9.2_s390x | 9.4_s390x | 9.6_s390x
- redhat•codeready_linux_builder_for_power_little_endian
9.0_ppc64le
- redhat•codeready_linux_builder_for_power_little_endian_eus
8.6 | 9.2_ppc64le | 9.4_ppc64le | 9.6_ppc64le
- redhat•enterprise_linux
8.0 | 9.0
- redhat•enterprise_linux_eus
8.6 | 9.2 | 9.4 | 9.6
- redhat•enterprise_linux_for_arm_64
9.0_aarch64
- redhat•enterprise_linux_for_arm_64_eus
8.6_aarch64 | 9.2_aarch64 | 9.4_aarch64 | 9.6_aarch64
- redhat•enterprise_linux_for_ibm_z_systems
9.0_s390x
- redhat•enterprise_linux_for_ibm_z_systems_eus
9.2_s390x | 9.4_s390x | 9.6_s390x
- redhat•enterprise_linux_for_ibm_z_systems_eus_s390x
8.6
- redhat•enterprise_linux_for_power_big_endian_eus
8.6_ppc64le
- redhat•enterprise_linux_for_power_little_endian
9.0_ppc64le
- redhat•enterprise_linux_for_power_little_endian_eus
9.2_ppc64le | 9.4_ppc64le | 9.6_ppc64le
- redhat•enterprise_linux_server_aus
8.6 | 9.2 | 9.4 | 9.6
- redhat•enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
9.2_ppc64le | 9.4_ppc64le | 9.6_ppc64le
- redhat•enterprise_linux_server_tus
8.6
- redhat•enterprise_linux_update_services_for_sap_solutions
9.2 | 9.4 | 9.6
- redhat•virtualization
4.0
- redhat•virtualization_host
4.0
- siemens•simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware
≥ 3.1.5
- siemens•simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware
≥ 3.1.5
- siemens•simatic_s7-1500_tm_mfp_firmware
< 1.1
- siemens•siplus_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware
≥ 3.1.5
References (30)
- https://access.redhat.com/errata/RHSA-2023:5453
- https://access.redhat.com/errata/RHSA-2023:5454
- https://access.redhat.com/errata/RHSA-2023:5455
- https://access.redhat.com/errata/RHSA-2023:5476
- https://access.redhat.com/errata/RHSA-2024:0033
- https://access.redhat.com/security/cve/CVE-2023-4911
- https://bugzilla.redhat.com/show_bug.cgi?id=2238352
- https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
- https://www.qualys.com/cve-2023-4911/
- http://packetstormsecurity.com/files/174986/glibc-ld.so-Local-Privilege-Escalation.html
- http://packetstormsecurity.com/files/176288/Glibc-Tunables-Privilege-Escalation.html
- http://seclists.org/fulldisclosure/2023/Oct/11
- http://www.openwall.com/lists/oss-security/2023/10/03/2
- http://www.openwall.com/lists/oss-security/2023/10/03/3
- http://www.openwall.com/lists/oss-security/2023/10/05/1
- http://www.openwall.com/lists/oss-security/2023/10/13/11
- http://www.openwall.com/lists/oss-security/2023/10/14/3
- http://www.openwall.com/lists/oss-security/2023/10/14/5
- http://www.openwall.com/lists/oss-security/2023/10/14/6
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/
- https://security.gentoo.org/glsa/202310-03
- https://security.netapp.com/advisory/ntap-20231013-0006/
- https://www.debian.org/security/2023/dsa-5514
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4911
- https://www.exploit-db.com/exploits/52479
- https://cert-portal.siemens.com/productcert/html/ssa-831302.html
- https://cert-portal.siemens.com/productcert/html/ssa-794697.html
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html