CVE-2023-4911

Updated: 2025-11-10 00:57:51.893635

Description:

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Known exploits

Added Date Description Due Date Notes
2023-11-21 GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges. 2023-12-12 This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa, https://access.redhat.com/security/cve/cve-2023-4911, https://www.debian.org/security/2023/dsa-5514 ; https://nvd.nist.gov/vuln/detail/CVE-2023-4911

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU glibc 2.34 7.8 HIGH Already Fixed 2023-11-08 08:36:01
CentOS 6 ELS glibc 2.12 7.8 HIGH Not Vulnerable 2023-11-23 10:12:40
CentOS 7 ELS glibc 2.17 7.8 HIGH Not Vulnerable 2023-12-22 04:13:08 Not affected
CentOS 8.4 ELS glibc 2.28 7.8 HIGH Not Vulnerable 2024-05-29 06:49:13 Not affected
CentOS 8.5 ELS glibc 2.28 7.8 HIGH Released CLSA-2023:1698312626 2023-10-26 07:39:15 Not affected
CentOS Stream 8 ELS glibc 2.28 7.8 HIGH Not Vulnerable 2024-05-21 10:11:59
CloudLinux 6 ELS glibc 2.12 7.8 HIGH Not Vulnerable 2023-11-23 10:12:39 Not affected
Oracle Linux 6 ELS glibc 2.12 7.8 HIGH Not Vulnerable 2023-11-23 10:12:39
TuxCare 9.6 ESU glibc 2.34 7.8 HIGH Already Fixed 2025-12-03 18:50:36
Ubuntu 16.04 ELS glibc 2.23-0 7.8 HIGH Not Vulnerable 2023-11-23 10:12:40 Not affected
Total: 11