CVE-2023-4911 Details
Description
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
A buffer overflow vulnerability has been identified in the dynamic loader of the GNU C Library (glibc) versions 2.35 through 2.37, excluding 2.34. This vulnerability, known as 'Looney Tunables', was introduced in glibc 2.34 and allows local attackers to exploit maliciously crafted GLIBC_TUNABLES environment variables when executing binaries with SUID permission. The exploitation can lead to unauthorized code execution with elevated privileges.
Users can update to glibc versions 2.39 or later, or apply the specific patch available in the Red Hat advisory RHSA-2023:5453. For Debian users, the update is included in glibc version 2.36-9+deb12u3.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| GNU C Library Buffer Overflow Vulnerability | Nov 21, 2023 | Dec 12, 2023 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| netapp bootstrap os | All versions |
CPE
Remediation
| |
| netapp hci compute node | All versions |
CPE
Remediation
| |
| siemens simatic s7-1500 cpu 1518-4 pn/dp mfp firmware | >= 3.1.5 |
CPE
Remediation
| |
| siemens simatic s7-1500 cpu 1518-4 pn/dp mfp | All versions |
CPE
Remediation
| |
| siemens simatic s7-1500 cpu 1518f-4 pn/dp mfp firmware | >= 3.1.5 |
CPE
Remediation
| |
| siemens simatic s7-1500 cpu 1518f-4 pn/dp mfp | All versions |
CPE
Remediation
| |
| siemens siplus s7-1500 cpu 1518-4 pn/dp mfp firmware | >= 3.1.5 |
CPE
Remediation
| |
| siemens siplus s7-1500 cpu 1518-4 pn/dp mfp | All versions |
CPE
Remediation
| |
| siemens simatic s7-1500 tm mfp firmware | < 1.1 |
CPE
Remediation
| |
| siemens simatic s7-1500 tm mfp | All versions |
CPE
Remediation
| |
| gnu glibc | >= 2.34, < 2.39 |
CPE
Remediation
| |
| fedoraproject fedora | 37 38 39 |
CPE
Remediation
| |
| redhat codeready linux builder | 9.0 |
CPE
Remediation
| |
| redhat codeready linux builder eus | 8.6 9.2 9.4 9.6 |
CPE
Remediation
| |
| redhat codeready linux builder for arm64 | 9.0_aarch64 |
CPE
Remediation
| |
| redhat codeready linux builder for arm64 eus | 8.6 9.2_aarch64 9.4_aarch64 9.6_aarch64 |
CPE
Remediation
| |
| redhat codeready linux builder for ibm z systems | 9.0_s390x |
CPE
Remediation
| |
| redhat codeready linux builder for ibm z systems eus | 8.6 9.2_s390x 9.4_s390x 9.6_s390x |
CPE
Remediation
| |
| redhat codeready linux builder for power little endian | 9.0_ppc64le |
CPE
Remediation
| |
| redhat codeready linux builder for power little endian eus | 8.6 9.2_ppc64le 9.4_ppc64le 9.6_ppc64le |
CPE
Remediation
| |
| redhat virtualization | 4.0 |
CPE
Remediation
| |
| redhat virtualization host | 4.0 |
CPE
Remediation
| |
| redhat enterprise linux | 8.0 9.0 |
CPE
Remediation
| |
| redhat enterprise linux eus | 8.6 9.2 9.4 9.6 |
CPE
Remediation
| |
| redhat enterprise linux for arm 64 | 9.0_aarch64 |
CPE
Remediation
| |
| redhat enterprise linux for arm 64 eus | 8.6_aarch64 9.2_aarch64 9.4_aarch64 9.6_aarch64 |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems | 9.0_s390x |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems eus | 9.2_s390x 9.4_s390x 9.6_s390x |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems eus s390x | 8.6 |
CPE
Remediation
| |
| redhat enterprise linux for power big endian eus | 8.6_ppc64le |
CPE
Remediation
| |
| redhat enterprise linux for power little endian | 9.0_ppc64le |
CPE
Remediation
| |
| redhat enterprise linux for power little endian eus | 9.2_ppc64le 9.4_ppc64le 9.6_ppc64le |
CPE
Remediation
| |
| redhat enterprise linux server aus | 8.6 9.2 9.4 9.6 |
CPE
Remediation
| |
| redhat enterprise linux server for power little endian update services for sap solutions | 9.2_ppc64le 9.4_ppc64le 9.6_ppc64le |
CPE
Remediation
| |
| redhat enterprise linux server tus | 8.6 |
CPE
Remediation
| |
| redhat enterprise linux update services for sap solutions | 9.2 9.4 9.6 |
CPE
Remediation
| |
| canonical ubuntu linux | 22.04 23.04 |
CPE
Remediation
| |
| debian debian linux | 11.0 12.0 |
CPE
Remediation
| |
| netapp h410c firmware | All versions |
CPE
Remediation
| |
| netapp h410c | All versions |
CPE
Remediation
| |
| netapp h300s firmware | All versions |
CPE
Remediation
| |
| netapp h300s | All versions |
CPE
Remediation
| |
| netapp h500s firmware | All versions |
CPE
Remediation
| |
| netapp h500s | All versions |
CPE
Remediation
| |
| netapp h700s firmware | All versions |
CPE
Remediation
| |
| netapp h700s | All versions |
CPE
Remediation
| |
| netapp h410s firmware | All versions |
CPE
Remediation
| |
| netapp h410s | All versions |
CPE
Remediation
| |
| netapp ontap select deploy administration utility | All versions |
CPE
Remediation
| |
Change History
41 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | Modified Analysis | [email protected] |
| May 12, 2026 | CVE Modified | siemens-SADP |
| Feb 13, 2026 | Modified Analysis | [email protected] |
| Feb 13, 2026 | CVE Modified | CVE |
| Jan 8, 2026 | Modified Analysis | [email protected] |
| Jan 8, 2026 | CVE Modified | [email protected] |
| Nov 6, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| May 6, 2025 | Modified Analysis | [email protected] |
| Apr 30, 2025 | CVE Modified | [email protected] |
| Jan 27, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Sep 17, 2024 | Modified Analysis | [email protected] |
| Sep 16, 2024 | CVE Modified | [email protected] |
| May 23, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 22, 2024 | Modified Analysis | [email protected] |
| Jan 3, 2024 | CVE Modified | [email protected] |
| Dec 21, 2023 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Oct 14, 2023 | CVE Modified | [email protected] |
| Oct 14, 2023 | CVE Modified | [email protected] |
| Oct 14, 2023 | CVE Modified | [email protected] |
| Oct 14, 2023 | CVE Modified | [email protected] |
| Oct 13, 2023 | CVE Modified | [email protected] |
| Oct 6, 2023 | CVE Modified | [email protected] |
| Oct 6, 2023 | CVE Modified | [email protected] |
| Oct 5, 2023 | CVE Modified | [email protected] |
| Oct 5, 2023 | Initial Analysis | [email protected] |
| Oct 5, 2023 | CVE Modified | [email protected] |
| Oct 5, 2023 | CVE Modified | [email protected] |
| Oct 4, 2023 | CVE Modified | [email protected] |
| Oct 4, 2023 | CVE Modified | [email protected] |
| Oct 4, 2023 | CVE Modified | [email protected] |
| Oct 3, 2023 | CVE Modified | [email protected] |
| Oct 3, 2023 | CVE Modified | [email protected] |