CVE-2023-4911

Looney Tunables: a buffer overflow in the dynamic loader, reachable by any local user

The dynamic loader runs with full privilege when it starts a setuid program, and it reads an environment variable the caller controls. That combination is a local root exploit, and CISA has it in the Known Exploited catalogue.

GNU C LibraryIn CISA’s Known Exploited catalogue since 2023-11-21EPSS 81.4% chance of an attempt in 30 daysCVSS 7.8CWE-122CWE-787CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A fixed package version is available on 5 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.

One read-only command. No account, no agent, nothing changed.

What it actually is

ld.so parses the GLIBC_TUNABLES environment variable when it loads a program. The parser mishandles a malformed value and overflows a buffer on the stack. Because the loader is already running as root by the time it does this for a setuid binary, the overflow happens with root privilege.

What an attacker gets: Full root from any local account, including a service account a web application runs as.

When it applies to you, and when it does not

An old package version and a real exposure are different things. These are the conditions this one needs.

  • Local only. Nothing about it is reachable across a network on its own.
  • What makes it serious is what it pairs with. Any foothold at all, a web shell running as www-data or a compromised FTP account, becomes root on an unpatched machine.
  • It needs a setuid binary to be present, which on any normal system means sudo, su, passwd and several others.

Check your own server

Read-only, changes nothing
ldd --version | head -1 && ls -l /usr/bin/sudo /bin/su

The glibc version and the presence of setuid binaries. Both are effectively always there, which is why the package version below is the answer.

Fixed package version, per distribution

From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.

ReleaseSource packageStateFixed in
Ubuntu 22.04 LTSglibcFixed2.35-0ubuntu3.4
Ubuntu 24.04 LTSglibcFixed2.38-1ubuntu6
Debian 12 (bookworm)glibcFixed2.36-9+deb12u3
Debian 13 (trixie)glibcFixed2.37-12
Rocky Linux 9glibcNo advisory names itno advisory for this release names it
AlmaLinux 9glibcFixed2.34-60.el9_2.7

Install the fix with apt update && apt install --only-upgrade libc6 libc-bin on Debian and Ubuntu, or dnf update glibc glibc-common on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.

What SecAI has recorded about it

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

Recorded from nvd. Its weakness class is CWE-122 and CWE-787, from NVD.

Read next

Check whether this vulnerability affects your Linux server

One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2023-4911 included. It changes nothing.