VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 20 hours ago

CVE-2023-4911

7.8 High Mitigation candidate

Description

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

CWE-122CWE-787 · Out-of-bounds write

Exploitation Status

Exploited in the wild

Confirmed real-world exploitation.

CVSS E:A

  • CISA KEV listed Confirmed exploitation in the wild. Added 2023-11-21 · remediation due 2023-12-12 · ransomware use: unknown
  • CISA Vulnrichment exploitation: active CISA records active exploitation. Automatable: no, technical impact: total.
  • Indexed PoC 20 indexed Published artifacts you can open, in Exploit-DB, GitHub PoC, Nuclei; first seen 2023-10-04.
  • EPSS 81% chance in 30 days A model prediction, not an observation. Higher than 100% of all scored CVEs.
IndexArtifactStarsFirst seen
GitHub PoC PoC for CVE-2023-4911 394 2023-10-04
Nuclei Looney Tunables Linux - Local Privilege Escalation
Exploit-DB glibc 2.38 - Buffer Overflow 2026-02-11
GitHub PoC CVE-2023-4911 proof of concept 167 2023-10-04
GitHub PoC Exploit tool for CVE-2023-4911, targeting the 'Looney Tunables' glibc vulnerability in various Linux distributions. 43 2023-10-17
GitHub PoC hadrian3689/looney-tunables-CVE-2023-4911 29 2023-10-10
GitHub PoC CVE-2023-4911 19 2023-10-11
GitHub PoC Looney Tunables Local privilege escalation (CVE-2023-4911) workshop 18 2023-10-25
GitHub PoC https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt 15 2023-10-04
GitHub PoC Repository containing a Proof of Concept (PoC) demonstrating the impact of CVE-2023-4911, a vulnerability in glibc's ld.so dynamic loader, exposing risks related to Looney Tunables. 8 2024-01-20

Waratek Defense Posture

Mitigation candidate

A defect of the type ARMR addresses, with a fix path to work from and a working exploit already published. This is a claim on attention, not a scheduling commitment: no rule exists and none is scheduled.

  • Protection none
  • Action unverified patch rule
  • Review automated inferred
  • Record active
Decided by patch-hint : A reference pointing at the upstream fix: a commit, a PR, a Red Hat bug
Finding Red Hat published an advisory () confirming a fix exists, and the linked Bugzilla ticket (https://bugzilla.redhat.com/show_bug.cgi?id=2238352) points to the upstream OpenJDK source patch. That makes this CVE a candidate for an ARMR patch rule. No rule exists and none is scheduled: whether one can be derived depends on reading the actual change.
Candidate fix https://bugzilla.redhat.com/show_bug.cgi?id=2238352 : a Red Hat bug: the triage, which links onward to the fix

CVSS

7.8 HIGH v3.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 2 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H secalert@redhat.com Secondary published
CVSS 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H NVD Primary

Affected Software & Releases

🏛️ Oracle CPU Advisories & Products

AdvisoryTypeQuarterProducts Oracle named in risk matrix
Oracle Critical Patch Update January 2024 CPU 2024-Q1 Oracle Communications / Signaling (glibc) (23.3.0)

Indexed Oracle Components & Versions

FamilyComponentOracle's version cell (verbatim)Indexed as
Oracle Communications Signaling (glibc) 23.3.0 23.3.0

🖥️ Product CPEs & Version Ranges

39 product(s) over 73 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd canonical ubuntu linux generic 22.04 · 23.04
nvd debian debian linux generic 11.0 · 12.0
nvd fedoraproject fedora generic 37 · 38 · 39
nvd gnu glibc generic ≥ 2.34 and < 2.39
nvd netapp bootstrap os generic any version
nvd netapp h300s firmware generic any version
nvd netapp h410c firmware generic any version
nvd netapp h410s firmware generic any version
nvd netapp h500s firmware generic any version
nvd netapp h700s firmware generic any version
nvd netapp ontap select deploy administration utility generic any version
nvd redhat codeready linux builder generic 9.0
nvd redhat codeready linux builder eus generic 8.6 · 9.2 · 9.4 · 9.6
nvd redhat codeready linux builder for arm64 generic 9.0_aarch64
nvd redhat codeready linux builder for arm64 eus generic 8.6 · 9.2_aarch64 · 9.4_aarch64 · 9.6_aarch64
nvd redhat codeready linux builder for ibm z systems generic 9.0_s390x
nvd redhat codeready linux builder for ibm z systems eus generic 8.6 · 9.2_s390x · 9.4_s390x · 9.6_s390x
nvd redhat codeready linux builder for power little endian generic 9.0_ppc64le
nvd redhat codeready linux builder for power little endian eus generic 8.6 · 9.2_ppc64le · 9.4_ppc64le · 9.6_ppc64le
nvd redhat enterprise linux generic 8.0 · 9.0
nvd redhat enterprise linux eus generic 8.6 · 9.2 · 9.4 · 9.6
nvd redhat enterprise linux for arm 64 generic 9.0_aarch64
nvd redhat enterprise linux for arm 64 eus generic 8.6_aarch64 · 9.2_aarch64 · 9.4_aarch64 · 9.6_aarch64
nvd redhat enterprise linux for ibm z systems generic 9.0_s390x
nvd redhat enterprise linux for ibm z systems eus generic 9.2_s390x · 9.4_s390x · 9.6_s390x
nvd redhat enterprise linux for ibm z systems eus s390x generic 8.6
nvd redhat enterprise linux for power big endian eus generic 8.6_ppc64le
nvd redhat enterprise linux for power little endian generic 9.0_ppc64le
nvd redhat enterprise linux for power little endian eus generic 9.2_ppc64le · 9.4_ppc64le · 9.6_ppc64le
nvd redhat enterprise linux server aus generic 8.6 · 9.2 · 9.4 · 9.6
nvd redhat enterprise linux server for power little endian update services for sap solutions generic 9.2_ppc64le · 9.4_ppc64le · 9.6_ppc64le
nvd redhat enterprise linux server tus generic 8.6
nvd redhat enterprise linux update services for sap solutions generic 9.2 · 9.4 · 9.6
nvd redhat virtualization generic 4.0
nvd redhat virtualization host generic 4.0
nvd siemens simatic s7-1500 cpu 1518-4 pn\/dp mfp firmware generic ≥ 3.1.5
nvd siemens simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware generic ≥ 3.1.5
nvd siemens simatic s7-1500 tm mfp firmware generic < 1.1
nvd siemens siplus s7-1500 cpu 1518-4 pn\/dp mfp firmware generic ≥ 3.1.5

References

URLTags
https://bugzilla.redhat.com/show_bug.cgi?id=2238352 bugzilla
https://sourceware.org/git/?p=glibc.git
https://access.redhat.com/security/cve/cve-2023-4911, https://www.debian.org/security/2023/dsa-5514
https://access.redhat.com/errata/RHSA-2023:5453 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:5454 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:5455 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:5476 Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0033 Third Party Advisory
https://access.redhat.com/security/cve/CVE-2023-4911 Third Party Advisory
https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt Exploit, Third Party Advisory

Timeline

Published 2023-10-03 Last modified 2026-06-17
Published2023-10-03By the CVE Program.
NVD record modified2026-06-17NVD's own last-modified date for this record.