CVE-2023-4911
03.10.2023, 18:15
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.Enginsight
Vendor | Product | Version |
---|---|---|
gnu | glibc | 2.34 ≤ 𝑥 < 2.39 |
redhat | codeready_linux_builder | 9.0 |
redhat | codeready_linux_builder_eus | 8.6 |
redhat | codeready_linux_builder_eus | 9.2 |
redhat | codeready_linux_builder_eus | 9.4 |
redhat | codeready_linux_builder_for_arm64 | 9.0_aarch64:_aarch64 |
redhat | codeready_linux_builder_for_arm64_eus | 8.6 |
redhat | codeready_linux_builder_for_arm64_eus | 9.2_aarch64:_aarch64 |
redhat | codeready_linux_builder_for_arm64_eus | 9.4_aarch64:_aarch64 |
redhat | codeready_linux_builder_for_ibm_z_systems | 9.0_s390x:_s390x |
redhat | codeready_linux_builder_for_ibm_z_systems_eus | 8.6 |
redhat | codeready_linux_builder_for_ibm_z_systems_eus | 9.2_s390x:_s390x |
redhat | codeready_linux_builder_for_ibm_z_systems_eus | 9.4_s390x:_s390x |
redhat | codeready_linux_builder_for_power_little_endian | 9.0_ppc64le:_ppc64le |
redhat | codeready_linux_builder_for_power_little_endian_eus | 8.6 |
redhat | codeready_linux_builder_for_power_little_endian_eus | 9.2_ppc64le:_ppc64le |
redhat | codeready_linux_builder_for_power_little_endian_eus | 9.4_ppc64le:_ppc64le |
redhat | virtualization | 4.0 |
redhat | virtualization_host | 4.0 |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux | 9.0 |
redhat | enterprise_linux_eus | 8.6 |
redhat | enterprise_linux_eus | 9.2 |
redhat | enterprise_linux_eus | 9.4 |
redhat | enterprise_linux_for_arm_64 | 9.0_aarch64:_aarch64 |
redhat | enterprise_linux_for_arm_64_eus | 8.6_aarch64:_aarch64 |
redhat | enterprise_linux_for_arm_64_eus | 9.2_aarch64:_aarch64 |
redhat | enterprise_linux_for_arm_64_eus | 9.4_aarch64:_aarch64 |
redhat | enterprise_linux_for_ibm_z_systems | 9.0_s390x:_s390x |
redhat | enterprise_linux_for_ibm_z_systems_eus | 9.2_s390x:_s390x |
redhat | enterprise_linux_for_ibm_z_systems_eus | 9.4_s390x:_s390x |
redhat | enterprise_linux_for_ibm_z_systems_eus_s390x | 8.6 |
redhat | enterprise_linux_for_power_big_endian_eus | 8.6_ppc64le:_ppc64le |
redhat | enterprise_linux_for_power_little_endian | 9.0_ppc64le:_ppc64le |
redhat | enterprise_linux_for_power_little_endian_eus | 9.2_ppc64le:_ppc64le |
redhat | enterprise_linux_for_power_little_endian_eus | 9.4_ppc64le:_ppc64le |
redhat | enterprise_linux_server_aus | 8.6 |
redhat | enterprise_linux_server_aus | 9.2 |
redhat | enterprise_linux_server_aus | 9.4 |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 9.2_ppc64le:_ppc64le |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 9.4_ppc64le:_ppc64le |
redhat | enterprise_linux_server_tus | 8.6 |
canonical | ubuntu_linux | 22.04 |
canonical | ubuntu_linux | 23.04 |
debian | debian_linux | 11.0 |
debian | debian_linux | 12.0 |
netapp | h410c_firmware | - |
netapp | h300s_firmware | - |
netapp | h500s_firmware | - |
netapp | h700s_firmware | - |
netapp | h410s_firmware | - |
netapp | ontap_select_deploy_administration_utility | - |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
eglibc |
| ||||||||||||||||
glibc |
|
Common Weakness Enumeration
- CWE-122 - Heap-based Buffer OverflowA heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
- CWE-787 - Out-of-bounds WriteThe software writes data past the end, or before the beginning, of the intended buffer.
References