High SEVERITY — Vulnerability

glibc "Looney Tunables" local privilege escalation — CVE-2023-4911

A buffer overflow in the dynamic loader allows obtaining root privileges via GLIBC_TUNABLES.

Platform
Ubuntu Server
Version
22.04 LTS / Jammy Jellyfish
CVE Record
CVE-2023-4911
CVSS Score
7.8/10
Advisory
USN-6407-1
Published
03 October 2023
Views
5
Primary source: Review the official advisory at ubuntu.com Kaynağa Git

Summary

A buffer overflow in the glibc dynamic loader while processing the GLIBC_TUNABLES environment variable (the Looney Tunables) grants full root access via SUID binaries.

Fix

For Ubuntu 22.04 the libc6 2.35-0ubuntu3.4 package was released with USN-6407-1. Restarting services after the update is required.

Ubuntu Server — Related Advisories

VIEW ALL →