CVE-2023-4911
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2023-4911 is a buffer overflow vulnerability affecting the GNU C Library's dynamic loader, ld.so. This issue arises when processing the GLIBC_TUNABLES environment variable. A local attacker can exploit this vulnerability by providing maliciously crafted GLIBC_TUNABLES variables when launching binaries with SUID permission. Successful exploitation could lead to the execution of arbitrary code with elevated privileges. The vulnerability poses a significant risk, particularly in environments where SUID binaries are frequently used. It is recommended that affected systems be updated as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Red Hat Enterprise Linux
- Fedora Operating System
- Red Hat Virtualization
Affected Vendors
- Red Hat
- Fedora Project