CVE-2023-4911
KEV PoC ×6mass1Buffer Overflow in GNU C Library ld.so Grants Root via SUID Binaries
CISA: GNU C Library Buffer Overflow Vulnerability
CVE-2023-4911 ('Looney Tunables') is a buffer overflow in the GNU C Library's dynamic loader (ld.so) that occurs while processing the GLIBC_TUNABLES environment variable. A local attacker triggers it by launching a set-user-ID (SUID) binary with a maliciously crafted GLIBC_TUNABLES value, corrupting memory in the privileged process. This allows the attacker to execute code with elevated (root) privileges on the host. Any system running an affected glibc is potentially exposed, including major Linux distributions (Fedora, Red Hat, Canonical, Debian), Red Hat CodeReady Linux Builder channels, NetApp products, and Siemens SIMATIC S7-1500 firmware, although exploitation requires local execution capability or a foothold on the machine. Exploitation is confirmed in the wild: Qualys published a working proof-of-concept, the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-21, and Kinsing threat actors have used it for cryptojacking and to breach cloud environments.
What to do: Install patched glibc updates from your distribution vendor (Fedora, Red Hat, Canonical/Ubuntu, Debian) and apply Siemens firmware updates for affected SIMATIC S7-1500 MFP devices; NetApp customers should follow NetApp's remediation guidance. Until patched, audit SUID/SGID binaries (which the attacker needs as the escalation trigger) and limit untrusted local access and shell access on multi-user or cloud-hosted Linux systems. Per the CISA KEV required action, apply vendor mitigations or discontinue use, prioritizing internet-facing hosts given active Kinsing cryptojacking and cloud-breach activity.
| gnu glibc | — |
| fedoraproject fedora | — |
| redhat codeready linux builder | — |
| redhat codeready linux builder eus | — |
| redhat codeready linux builder for arm64 | — |
| redhat codeready linux builder for arm64 eus | — |
| redhat codeready linux builder for ibm z systems | — |
| siemens simatic s7-1500 cpu 1518-4 pn/dp mfp firmware | — |
| siemens simatic s7-1500 cpu 1518f-4 pn/dp mfp firmware | — |
| siemens siplus s7-1500 cpu 1518-4 pn/dp mfp firmware | — |
| siemens simatic s7-1500 tm mfp firmware | — |
| netapp bootstrap os | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
- Affected
- GNU GNU C Library
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- netappsiemensgnufedoraprojectredhatcanonicaldebian
- Products
- bootstrap os, simatic s7-1500 cpu 1518-4 pn\/dp mfp firmware, simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware, siplus s7-1500 cpu 1518-4 pn\/dp mfp firmware, simatic s7-1500 tm mfp firmware, glibc, fedora, codeready linux builder, codeready linux builder eus, codeready linux builder for arm64, codeready linux builder for arm64 eus, codeready linux builder for ibm z systems
- Weakness
- CWE-122, CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H