CVE-2025-4802

The setuid LD_LIBRARY_PATH flaw: a search path that should have been ignored, and was not

A setuid program is supposed to ignore the library search path its caller sets, for the obvious reason. Under specific conditions glibc honoured it anyway.

GNU C LibraryNot in CISA’s Known Exploited catalogueEPSS 0.56% chance of an attempt in 30 daysCVSS 7.8CWE-426CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A fixed package version is available on 5 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.

One read-only command. No account, no agent, nothing changed.

What it actually is

When a statically linked setuid program calls dlopen, glibc consulted LD_LIBRARY_PATH from the environment rather than ignoring it as it does for dynamically linked setuid binaries. An attacker who can set that variable can then have their own library loaded with the program's privileges.

What an attacker gets: Code execution with the privileges of the setuid program, which in the usual case means root.

When it applies to you, and when it does not

An old package version and a real exposure are different things. These are the conditions this one needs.

  • It needs a statically linked setuid binary that calls dlopen, which is an unusual combination. Most distributions ship few or none.
  • Local only, and it needs the attacker to control the environment of the process being started.
  • Worth patching on principle rather than because a known exploitable binary is on your box. The point of the rule glibc broke is that you should not have to audit for one.

Check your own server

Read-only, changes nothing
find /usr/bin /usr/sbin /bin /sbin -perm -4000 -type f 2>/dev/null | head -30

Lists the setuid binaries actually present. This is worth reading occasionally regardless of this CVE.

Fixed package version, per distribution

From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.

ReleaseSource packageStateFixed in
Ubuntu 22.04 LTSglibcFixed2.35-0ubuntu3.10
Ubuntu 24.04 LTSglibcNo advisory names itno advisory for this release names it
Debian 12 (bookworm)glibcFixed2.36-9+deb12u11
Debian 13 (trixie)glibcFixed2.39-4
Rocky Linux 9glibcFixed0:2.34-168.el9_6.19
AlmaLinux 9glibcFixed2.34-168.el9_6.19

Install the fix with apt update && apt install --only-upgrade libc6 libc-bin on Debian and Ubuntu, or dnf update glibc glibc-common on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.

What SecAI has recorded about it

Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).

Recorded from nvd. Its weakness class is CWE-426, from NVD.

Read next

Check whether this vulnerability affects your Linux server

One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2025-4802 included. It changes nothing.