PoC Index

CVE-2023-4911

KEVHIGH 7.8EPSS 81.4%

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
81.42% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2023-11-21
Nuclei
high
Published
2023-10-03
Updated
2026-07-14

Proof-of-concept exploits (23)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (1)

References

Related