Cyber Resilience

CVE-2023-4911

HighCISA KEVActive ExploitationEUVD ExploitedPublic PoC

Published: 03 October 2023

Published
03 October 2023
Modified
12 May 2026
KEV Added
21 November 2023
Patch
CVSS Score v3.1 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.7861 99.5th percentile
Risk Priority 100 floored blend · peak EPSS

Summary

CVE-2023-4911 is a high-severity Heap-based Buffer Overflow (CWE-122) vulnerability in Redhat Codeready Linux Builder Eus. Its CVSS base score is 7.8 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked in the top 0.5% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.

The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-2 (Flaw Remediation).

Deeper analysis

A buffer overflow vulnerability exists in the GNU C Library dynamic loader ld.so during handling of the GLIBC_TUNABLES environment variable. The flaw, tracked as CVE-2023-4911 and assigned CVSS 7.8, affects the processing logic that can be reached when SUID binaries are executed and matches CWE-122 and CWE-787.

A local attacker with the ability to set environment variables can supply a maliciously crafted GLIBC_TUNABLES value when invoking an SUID binary. Successful exploitation grants arbitrary code execution with the privileges of the binary owner, typically root.

Red Hat has published the advisories RHSA-2023:5453, RHSA-2023:5454, RHSA-2023:5455, RHSA-2023:5476, and RHSA-2024:0033 that deliver patched glibc packages. The associated EPSS score reached a peak of 0.7426 and currently stands at 0.6505, indicating material post-disclosure exploitation interest.

EU & UK References

Vulnerability details

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to…

more

execute code with elevated privileges.

CWE(s)
KEV Date Added
21 November 2023

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Why these techniques?

CVE-2023-4911 is a buffer overflow in glibc's ld.so exploitable via crafted GLIBC_TUNABLES environment variable when launching SUID binaries, enabling local privilege escalation.

CVEs Like This One

CVE-2022-0847Same product: Fedoraproject Fedoraboth on KEV
CVE-2025-24928Same product: Netapp H300S
CVE-2024-54085Same product: Netapp H300Sboth on KEV
CVE-2025-30273Same product class: NAS / storage appliance
CVE-2024-53697Same product class: NAS / storage appliance
CVE-2025-24813Same product: Debian Debian Linuxboth on KEV
CVE-2020-1472Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2021-3156Same product: Debian Debian Linuxboth on KEV
CVE-2021-44228Same product: Debian Debian Linuxboth on KEV
CVE-2025-57709Same product class: NAS / storage appliance

Affected Assets

netapp
bootstrap os
all versions
siemens
simatic s7-1500 cpu 1518-4 pn\/dp mfp firmware
≥ 3.1.5
siemens
simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware
≥ 3.1.5
siemens
siplus s7-1500 cpu 1518-4 pn\/dp mfp firmware
≥ 3.1.5
siemens
simatic s7-1500 tm mfp firmware
≤ 1.1
gnu
glibc
2.34 — 2.39
fedoraproject
fedora
37, 38, 39
redhat
codeready linux builder
9.0
redhat
codeready linux builder eus
8.6, 9.2, 9.4, 9.6
redhat
codeready linux builder for arm64
9.0_aarch64
+29 more product configuration(s) — see NVD for full list

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

prevent

Directly requires applying the Red Hat errata patches that eliminate the vulnerable ld.so buffer-overflow code handling GLIBC_TUNABLES.

prevent

Mandates input validation on untrusted data (here the GLIBC_TUNABLES environment variable) before it is expanded by the dynamic loader.

prevent

Requires minimizing the set of SUID/SGID binaries that an attacker can invoke with a crafted environment, thereby reducing the attack surface for local privilege escalation.

References