← Back

CVE-2023-4911

Published: Oct 3, 2023Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

Affected (73)

Show all products
7 products
Bootstrap Os
H410c Firmware
H300s Firmware
H500s Firmware
H700s Firmware
H410s Firmware
4 products
1 product
Glibc
1 product
Fedora
24 products
1 product
Ubuntu Linux
1 product
Debian Linux
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Hci Compute Node
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 3.1.5
Running on/withPlatform Versions
Siemens
Simatic S7 1500 Cpu 1518 4 Pn/dp Mfp
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 3.1.5
Running on/withPlatform Versions
Siemens
Simatic S7 1500 Cpu 1518f 4 Pn/dp Mfp
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 3.1.5
Running on/withPlatform Versions
Siemens
Siplus S7 1500 Cpu 1518 4 Pn/dp Mfp
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1
Running on/withPlatform Versions
Siemens
Simatic S7 1500 Tm Mfp
All versions
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.34 to 2.39
Configuration G
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 37
Version 38
Version 39
Configuration H
54 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Redhat
Version 8.6
Version 9.2
Version 9.4
Version 9.6
Version 9.0_aarch64
Redhat
Version 8.6
Version 9.2_aarch64
Version 9.4_aarch64
Version 9.6_aarch64
Version 9.0_s390x
Redhat
Version 8.6
Version 9.2_s390x
Version 9.4_s390x
Version 9.6_s390x
Version 9.0_ppc64le
Redhat
Version 8.6
Version 9.2_ppc64le
Version 9.4_ppc64le
Version 9.6_ppc64le
Redhat
Version 8.0
Version 9.0
Redhat
Version 8.6
Version 9.2
Version 9.4
Version 9.6
Version 9.0_aarch64
Redhat
Version 8.6_aarch64
Version 9.2_aarch64
Version 9.4_aarch64
Version 9.6_aarch64
Version 9.0_s390x
Redhat
Version 9.2_s390x
Version 9.4_s390x
Version 9.6_s390x
Version 8.6
Version 8.6_ppc64le
Version 9.0_ppc64le
Redhat
Version 9.2_ppc64le
Version 9.4_ppc64le
Version 9.6_ppc64le
Redhat
Version 8.6
Version 9.2
Version 9.4
Version 9.6
Redhat
Version 9.2_ppc64le
Version 9.4_ppc64le
Version 9.6_ppc64le
Version 8.6
Redhat
Version 9.2
Version 9.4
Version 9.6
Version 4.0
Version 4.0
Configuration I
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 22.04
Version 23.04
Debian
Version 11.0
Version 12.0
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H410c
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H300s
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H500s
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H700s
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H410s
All versions
Configuration O
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (39)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingPatch
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Third Party Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Third Party Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.