CVE-2023-4911

ADVISORY - nist

Summary

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

EPSS Score: 0.78156 (0.990)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Heap-based Buffer Overflow

Out-of-bounds Write

ADVISORY - redhat

Heap-based Buffer Overflow


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in