glibc "Looney Tunables" local privilege escalation — CVE-2023-4911
A buffer overflow in the dynamic loader allows obtaining root privileges via GLIBC_TUNABLES.
A buffer overflow in the dynamic loader allows obtaining root privileges via GLIBC_TUNABLES.
A buffer overflow in the glibc dynamic loader while processing the GLIBC_TUNABLES environment variable (the Looney Tunables) grants full root access via SUID binaries.
For Ubuntu 22.04 the libc6 2.35-0ubuntu3.4 package was released with USN-6407-1. Restarting services after the update is required.
The kernel update released for Ubuntu 24.04 LTS addresses a use-after-free vulnerability in the nf_tables component.
A signal handler race condition in the OpenSSH server carries a risk of unauthenticated RCE as root.
Bulk security patches for the OpenSSL, curl, sudo and systemd packages were published this month.