CVE-2023-4911
Last modified
CVE-2023-4911 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.. CISA has confirmed active exploitation in the wild. EPSS estimates a 78.61% chance of exploitation in the next 30 days.
Description
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netapp | Bootstrap Os | All versions |
| Siemens | Simatic S7-1500 Cpu 1518-4 Pn\/Dp Mfp Firmware | >= 3.1.5 |
| Siemens | Simatic S7-1500 Cpu 1518f-4 Pn\/Dp Mfp Firmware | >= 3.1.5 |
| Siemens | Siplus S7-1500 Cpu 1518-4 Pn\/Dp Mfp Firmware | >= 3.1.5 |
| Siemens | Simatic S7-1500 Tm Mfp Firmware | < 1.1 |
| Gnu | Glibc | >= 2.34, < 2.39 |
| Fedoraproject | Fedora | 37 |
| Fedoraproject | Fedora | 38 |
| Fedoraproject | Fedora | 39 |
| Redhat | Codeready Linux Builder | 9.0 |
| Redhat | Codeready Linux Builder Eus | 8.6 |
| Redhat | Codeready Linux Builder Eus | 9.2 |
| Redhat | Codeready Linux Builder Eus | 9.4 |
| Redhat | Codeready Linux Builder Eus | 9.6 |
| Redhat | Codeready Linux Builder For Arm64 | 9.0_aarch64 |
| Redhat | Codeready Linux Builder For Arm64 Eus | 8.6 |
| Redhat | Codeready Linux Builder For Arm64 Eus | 9.2_aarch64 |
| Redhat | Codeready Linux Builder For Arm64 Eus | 9.4_aarch64 |
| Redhat | Codeready Linux Builder For Arm64 Eus | 9.6_aarch64 |
| Redhat | Codeready Linux Builder For Ibm Z Systems | 9.0_s390x |
| Redhat | Codeready Linux Builder For Ibm Z Systems Eus | 8.6 |
| Redhat | Codeready Linux Builder For Ibm Z Systems Eus | 9.2_s390x |
| Redhat | Codeready Linux Builder For Ibm Z Systems Eus | 9.4_s390x |
| Redhat | Codeready Linux Builder For Ibm Z Systems Eus | 9.6_s390x |
| Redhat | Codeready Linux Builder For Power Little Endian | 9.0_ppc64le |
| Redhat | Codeready Linux Builder For Power Little Endian Eus | 8.6 |
| Redhat | Codeready Linux Builder For Power Little Endian Eus | 9.2_ppc64le |
| Redhat | Codeready Linux Builder For Power Little Endian Eus | 9.4_ppc64le |
| Redhat | Codeready Linux Builder For Power Little Endian Eus | 9.6_ppc64le |
| Redhat | Virtualization | 4.0 |
| Redhat | Virtualization Host | 4.0 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux | 9.0 |
| Redhat | Enterprise Linux Eus | 8.6 |
| Redhat | Enterprise Linux Eus | 9.2 |
| Redhat | Enterprise Linux Eus | 9.4 |
| Redhat | Enterprise Linux Eus | 9.6 |
| Redhat | Enterprise Linux For Arm 64 | 9.0_aarch64 |
| Redhat | Enterprise Linux For Arm 64 Eus | 8.6_aarch64 |
| Redhat | Enterprise Linux For Arm 64 Eus | 9.2_aarch64 |
| Redhat | Enterprise Linux For Arm 64 Eus | 9.4_aarch64 |
| Redhat | Enterprise Linux For Arm 64 Eus | 9.6_aarch64 |
| Redhat | Enterprise Linux For Ibm Z Systems | 9.0_s390x |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 9.2_s390x |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 9.4_s390x |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 9.6_s390x |
| Redhat | Enterprise Linux For Ibm Z Systems Eus S390x | 8.6 |
| Redhat | Enterprise Linux For Power Big Endian Eus | 8.6_ppc64le |
| Redhat | Enterprise Linux For Power Little Endian | 9.0_ppc64le |
| Redhat | Enterprise Linux For Power Little Endian Eus | 9.2_ppc64le |
Showing 50 of 73 affected configurations. See NVD for the full list.
References
- https://access.redhat.com/errata/RHSA-2023:5453Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:5454Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:5455Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:5476Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0033Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-4911Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2238352Issue Tracking, Patch
- https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txtExploit, Third Party Advisory
- https://www.qualys.com/cve-2023-4911/Third Party Advisory
- https://packetstormsecurity.com/files/174986/glibc-ld.so-Local-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/176288/Glibc-Tunables-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2023/Oct/11Exploit, Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2023/10/03/2Exploit, Mailing List
- https://access.redhat.com/errata/RHSA-2023:5453Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:5454Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:5455Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:5476Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0033Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-4911Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2238352Issue Tracking, Patch
- https://security.gentoo.org/glsa/202310-03Third Party Advisory
- https://security.netapp.com/advisory/ntap-20231013-0006/Third Party Advisory
- https://www.debian.org/security/2023/dsa-5514Mailing List
- https://www.exploit-db.com/exploits/52479Exploit, Third Party Advisory, VDB Entry
- https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txtExploit, Third Party Advisory
- https://www.qualys.com/cve-2023-4911/Third Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlThird Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-794697.htmlThird Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-831302.htmlThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4911US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-4911?
How severe is CVE-2023-4911?
How do I fix CVE-2023-4911?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-49104An issue was discovered in ownCloud owncloud/oauth2 before 0…6.1
- CVE-2023-49105An issue was discovered in ownCloud owncloud/core before 10.…9.8
- CVE-2023-49106Missing Password Field Masking vulnerability in Hitachi Devi…7.5
- CVE-2023-49107Generation of Error Message Containing Sensitive Information…7.5
- CVE-2023-49108Path traversal vulnerability exists in RakRak Document Plus …8.8
- CVE-2023-49109Exposure of Remote Code Execution in Apache Dolphinscheduler…9.8
- CVE-2023-49110When the Kiuwan Local Analyzer uploads the scan results to t…7.2
- CVE-2023-49111For Kiuwan installations with SSO (single sign-on) enabled, …6.5
- CVE-2023-49112Kiuwan provides an API endpoint /saas/rest/v1/info/applicat…6.5
- CVE-2023-49113The Kiuwan Local Analyzer (KLA) Java scanning application co…7.8
- CVE-2023-49114A DLL hijacking vulnerability was identified in the Qognify …6.7
- CVE-2023-49115 MachineSense devices use unauthenticated MQTT messagi…7.5
Are you affected by CVE-2023-4911?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
