Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 81.4%; technical severity is CVSS 7.8.
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Who should care
- Teams operating Ubuntu Linux, Debian Linux, Fedora +37 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Ubuntu Linux, Debian Linux, Fedora +37 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Red Hat Security patch Show Bug.cgi
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Advisory
Technical details
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-122
- Affected versions
- Canonical Ubuntu Linux (Version 22.04 | Version 23.04); Debian Debian Linux (Version 11.0 | Version 12.0); Fedoraproject Fedora (Version 37 | Version 38 | Version 39); GNU Glibc (Start Including 2.34, End Excluding 2.39); GNU GNU C Library; Netapp Bootstrap Os (Version -); Netapp H300s Firmware (Version -); Netapp H410c Firmware (Version -)
- Fixed versions
- GNU Glibc (Fixed from 2.39); Siemens Simatic S7-1500 Tm Mfp Firmware (Fixed from 1.1)
- Published
- 3 October 2023
- Attack vector
- Local
- Privileges required
- Low
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 81.4%
- Signal calculated at 81
External references
- Red Hat Third-party advisory RHSA-2023:5453
- Red Hat Third-party advisory RHSA-2023:5454
- Red Hat Third-party advisory RHSA-2023:5455
- Red Hat Third-party advisory RHSA-2023:5476
- Red Hat Third-party advisory RHSA-2024:0033
- CISA Government advisory CVE-2023-4911
- Exploit information from www.qualys.com
- Qualys Third-party advisory CVE-2023-4911
- Exploit information from packetstormsecurity.com
- Exploit information from packetstormsecurity.com
- Exploit information from seclists.org
- Exploit information from www.openwall.com