CVE-2023-4911: GNU C Library Buffer Overflow Vulnerability

Published Sep 11, 2023
·
Updated

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBCTUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBCTUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

Other sources

glibc could allow a local authenticated attacker to gain elevated privileges on the system, caused by a buffer overflow in the dynamic loader's processing of the GLIBCTUNABLES environment variable. By sending overly long data, an attacker could exploit this vulnerability to gain root privileges on the system.

IBM

Glibc: buffer overflow in ld.so leading to privilege escalation

Microsoft

GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBCTUNABLES environment variable, allowing a local attacker to execute code with elevated privileges.

CISA

Researchers discovered a vulnerability in the GNU C Library's dynamic loader (ld.so). This vulnerability was introduced in April 2021 (glibc 2.34) by the following commit: https://sourceware.org/git?p=glibc.git;a=commit;h=2ed18c5b534d9e92fc006202a5af0df6b72e7aca

Per researchers this vulnerability is exploitable by any local user and can lead to privilege escalation when combined with almost any SUID-root binaries.

Red Hat

Affected Software

97 affected componentsFixes available
ubuntu/glibc<2.35-0ubuntu3.4
2.35-0ubuntu3.4
ubuntu/glibc<2.37-0ubuntu2.1
2.37-0ubuntu2.1
ubuntu/glibc<2.38-1ubuntu6
2.38-1ubuntu6
debian/glibc<=2.31-13+deb11u6
2.28-10+deb10u12.28-10+deb10u22.31-13+deb11u72.36-9+deb12u32.37-122.37-13
GNU GNU C Library
GNU C Library (glibc)=2.37
GNU C Library (glibc)=2.36
GNU glibc
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Fedoraproject Fedora=39
redhat Virtualization=4.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
IBM Security Verify Governance, Identity Manager software component<=ISVG 10.0.2
IBM Security Verify Governance, Identity Manager virtual appliance component<=ISVG 10.0.2
Microsoft cbl2 glibc 2.35-5
Microsoft azl3 glibc 2.38-6
Microsoft azl3 glibc 2.38-10
redhat/glibc<2.39
2.39
All of the following
NetApp Bootstrap Os
NetApp Hci Compute Node
GNU glibc>=2.34<2.39
redhat Codeready Linux Builder=9.0
redhat Codeready Linux Builder Eus=8.6
redhat Codeready Linux Builder Eus=9.2
redhat Codeready Linux Builder Eus=9.4
redhat Codeready Linux Builder Eus=9.6
redhat Codeready Linux Builder For Arm64=9.0_aarch64
redhat Codeready Linux Builder For Arm64 Eus=8.6
redhat Codeready Linux Builder For Arm64 Eus=9.2_aarch64
redhat Codeready Linux Builder For Arm64 Eus=9.4_aarch64
redhat Codeready Linux Builder For Arm64 Eus=9.6_aarch64
redhat Codeready Linux Builder For Ibm Z Systems=9.0_s390x
redhat Codeready Linux Builder For Ibm Z Systems Eus=8.6
redhat Codeready Linux Builder For Ibm Z Systems Eus=9.2_s390x
redhat Codeready Linux Builder For Ibm Z Systems Eus=9.4_s390x
redhat Codeready Linux Builder For Ibm Z Systems Eus=9.6_s390x
redhat Codeready Linux Builder For Power Little Endian=9.0_ppc64le
redhat Codeready Linux Builder For Power Little Endian Eus=8.6
redhat Codeready Linux Builder For Power Little Endian Eus=9.2_ppc64le
redhat Codeready Linux Builder For Power Little Endian Eus=9.4_ppc64le
redhat Codeready Linux Builder For Power Little Endian Eus=9.6_ppc64le
redhat Virtualization Host=4.0
redhat Enterprise Linux Eus=8.6
redhat Enterprise Linux Eus=9.2
redhat Enterprise Linux Eus=9.4
redhat Enterprise Linux Eus=9.6
redhat Enterprise Linux For Arm 64=9.0_aarch64
redhat Enterprise Linux For Arm 64 Eus=8.6_aarch64
redhat Enterprise Linux For Arm 64 Eus=9.2_aarch64
redhat Enterprise Linux For Arm 64 Eus=9.4_aarch64
redhat Enterprise Linux For Arm 64 Eus=9.6_aarch64
redhat Enterprise Linux For Ibm Z Systems=9.0_s390x
redhat Enterprise Linux For Ibm Z Systems Eus=9.2_s390x
redhat Enterprise Linux For Ibm Z Systems Eus=9.4_s390x
redhat Enterprise Linux For Ibm Z Systems Eus=9.6_s390x
redhat Enterprise Linux For Ibm Z Systems Eus S390x=8.6
redhat Enterprise Linux For Power Big Endian Eus=8.6_ppc64le
redhat Enterprise Linux For Power Little Endian=9.0_ppc64le
redhat Enterprise Linux For Power Little Endian Eus=9.2_ppc64le
redhat Enterprise Linux For Power Little Endian Eus=9.4_ppc64le
redhat Enterprise Linux For Power Little Endian Eus=9.6_ppc64le
redhat Enterprise Linux Server Aus=8.6
redhat Enterprise Linux Server Aus=9.2
redhat Enterprise Linux Server Aus=9.4
redhat Enterprise Linux Server Aus=9.6
redhat Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions=9.2_ppc64le
redhat Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions=9.4_ppc64le
redhat Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions=9.6_ppc64le
redhat Enterprise Linux Server Tus=8.6
redhat Enterprise Linux Update Services For Sap Solutions=9.2
redhat Enterprise Linux Update Services For Sap Solutions=9.4
redhat Enterprise Linux Update Services For Sap Solutions=9.6
Canonical Ubuntu Linux=22.04
Canonical Ubuntu Linux=23.04
Debian Debian Linux=11.0
Debian Debian Linux=12.0
All of the following
NetApp H410c Firmware
NetApp H410c
All of the following
NetApp H300s Firmware
NetApp H300s
All of the following
NetApp H500s Firmware
NetApp H500s
All of the following
NetApp H700s Firmware
NetApp H700s
All of the following
NetApp H410s Firmware
NetApp H410s
NetApp ONTAP Select Deploy administration utility
All of the following
Siemens Simatic S7-1500 Cpu 1518-4 Pn\/dp Mfp Firmware>=3.1.5
Siemens Simatic S7-1500 Cpu 1518-4 Pn\/dp Mfp
All of the following
Siemens Simatic S7-1500 Cpu 1518f-4 Pn\/dp Mfp Firmware>=3.1.5
Siemens Simatic S7-1500 Cpu 1518f-4 Pn\/dp Mfp
All of the following
Siemens Siplus S7-1500 Cpu 1518-4 Pn\/dp Mfp Firmware>=3.1.5
Siemens Siplus S7-1500 Cpu 1518-4 Pn\/dp Mfp
All of the following
Siemens Simatic S7-1500 Tm Mfp Firmware<1.1
Siemens Simatic S7-1500 Tm Mfp

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ubuntu/glibc to a version that resolves this vulnerability.

    Fixed in 2.35-0ubuntu3.4
  2. Upgrade

    Upgrade ubuntu/glibc to a version that resolves this vulnerability.

    Fixed in 2.37-0ubuntu2.1
  3. Upgrade

    Upgrade ubuntu/glibc to a version that resolves this vulnerability.

    Fixed in 2.38-1ubuntu6
  4. Upgrade

    Upgrade debian/glibc to a version that resolves this vulnerability.

    Fixed in 2.28-10+deb10u1Fixed in 2.28-10+deb10u2Fixed in 2.31-13+deb11u7Fixed in 2.36-9+deb12u3Fixed in 2.37-12Fixed in 2.37-13
  5. Upgrade

    Upgrade redhat/glibc to a version that resolves this vulnerability.

    Fixed in 2.39
  6. Compensating control

    Mitigate CVE-2023-4911 by applying mitigations per vendor instructions; if mitigations are unavailable, discontinue use of the product.

Event History

Sep 11, 2023
Data Sourced
via Red Hat·03:23 PM
DescriptionSeverityAffected Software
Oct 3, 2023
CVE Published
12:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 5, 2023
News Published
09:34 PM
Oct 15, 2023
Data Sourced
08:34 PM
Description
Nov 21, 2023
Known Exploited
via CISA·12:00 AM
News Published
05:56 PM
Jan 30, 2024
News Published
via BleepingComputer·11:06 PM
News Published
via BleepingComputer·11:07 PM
Feb 11, 2026
Exploit Published
via ExploitDB·12:00 AM

Parent advisories

This vulnerability appears in the following advisories.

Peer vulnerabilities

Found alongside the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2023-4911?

CVE-2023-4911 is a vulnerability in the GNU C Library's dynamic loader ld.so, which allows a local attacker to escalate privileges on the system.

2

What is the severity of CVE-2023-4911?

CVE-2023-4911 has a severity score of 7.8 (High).

3

How does CVE-2023-4911 affect glibc?

CVE-2023-4911 affects glibc versions 2.35-0ubuntu3.4 and 2.37-0ubuntu2.1 on Ubuntu, and versions 2.28-10+deb10u1, 2.28-10+deb10u2, 2.31-13+deb11u7, and 2.36-9+deb12u3 on Debian.

4

How can a local attacker exploit CVE-2023-4911?

A local attacker can exploit CVE-2023-4911 by using maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission, allowing them to execute arbitrary code.

5

How can I fix CVE-2023-4911?

To fix CVE-2023-4911, update glibc to the recommended versions provided by the vendor or distribution, such as version 2.35-0ubuntu3.4 for Ubuntu or version 2.31-13+deb11u7 for Debian.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203