Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-4911

98
FAUCET Score

CVE-2023-4911 is a critical buffer overflow vulnerability in the GNU C Library's dynamic loader (ld.so), affecting major Linux distributions like Canonical, Debian, Fedora, and Red Hat. This flaw allows a local attacker to achieve elevated privileges by crafting malicious GLIBC_TUNABLES environment variables when launching SUID binaries. With a CVSS score of 7.8 (High) and a FAUCET Risk Score of 100/100, the vulnerability presents a significant risk due to its potential for full system compromise (Confidentiality, Integrity, Availability). Notably, it is actively exploited in the wild, with public exploit code available (Metasploit, Nuclei, ExploitDB), and has garnered extensive community discussion and media coverage, including a CISA directive for federal agencies to patch.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
>= 3.1.5CPE matchmatch criteria
cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware:*:*:*:*:*:*:*:*
>= 3.1.5CPE matchmatch criteria
cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware:*:*:*:*:*:*:*:*
>= 3.1.5CPE matchmatch criteria
cpe:2.3:o:siemens:siplus_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware:*:*:*:*:*:*:*:*
< 1.1CPE matchmatch criteria
cpe:2.3:o:siemens:simatic_s7-1500_tm_mfp_firmware:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
81.42%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Nov 21, 2023
Metasploit: Glibc Tunables Privilege Escalation CVE-2023-4911 (aka Looney Tunables) · Oct 3, 2023
Nuclei: CVE-2023-4911 · Oct 26, 2023
ExploitDB: EDB-52479 · Feb 11, 2026
This CVE's current EPSS score of 0.8142 is in the 100th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (15)

microsoftpatch availablevia msrc
Product: cbl2 glibc 2.35-5 on CBL Mariner 2.0Fixed in: 2.35-5
microsoftpatch availablevia msrc
Product: azl3 glibc 2.38-6 on Azure Linux 3.0Fixed in: 2.38-6
microsoftpatch availablevia msrc
Product: azl3 glibc 2.38-10 on Azure Linux 3.0Fixed in: 2.38-6
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 2.35-5
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 2.35-5
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 2.38-6
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 2.38-6
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: redhat-virtualization-host-0:4.5.3-202312060823_8.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: glibc-0:2.28-225.el8_8.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: glibc-0:2.28-189.6.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: glibc-0:2.34-60.el9_2.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: glibc-0:2.34-28.el9_0.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: glibc-0:2.28-189.6.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: redhat-release-virtualization-host-0:4.5.3-10.el8ev
View patch

Vendor Advisories (3)

microsoft2024-Jul/CVE-2023-4911

CVE-2023-4911

Jul 9, 2024
microsoft2023-Oct/CVE-2023-4911Important

Glibc: buffer overflow in ld.so leading to privilege escalation

Oct 10, 2023
redhatCVE-2023-4911Important

glibc: buffer overflow in ld.so leading to privilege escalation

Oct 3, 2023

References

cert-portal.siemens.com / productcert/html/ssa-082556.html
Third Party Advisory
cert-portal.siemens.com / productcert/html/ssa-794697.html
Third Party Advisory
cert-portal.siemens.com / productcert/html/ssa-831302.html
Third Party Advisory
cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
packetstormsecurity.com / files/174986/glibc-ld.so-Local-Privilege-Escalation.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/176288/Glibc-Tunables-Privilege-Escalation.html
ExploitThird Party AdvisoryVDB Entry
seclists.org / fulldisclosure/2023/Oct/11
ExploitMailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR
Mailing List
security.gentoo.org / glsa/202310-03
Third Party Advisory
security.netapp.com / advisory/ntap-20231013-0006
Third Party Advisory
debian.org / security/2023/dsa-5514
Mailing List
exploit-db.com / exploits/52479
ExploitThird Party AdvisoryVDB Entry
openwall.com / lists/oss-security/2023/10/03/2
ExploitMailing List
openwall.com / lists/oss-security/2023/10/03/3
Mailing List
openwall.com / lists/oss-security/2023/10/05/1
Mailing List
openwall.com / lists/oss-security/2023/10/13/11
Mailing List
openwall.com / lists/oss-security/2023/10/14/3
Mailing List
openwall.com / lists/oss-security/2023/10/14/5
Mailing List
openwall.com / lists/oss-security/2023/10/14/6
Mailing List
access.redhat.com / errata/RHSA-2023:5453
Third Party Advisory
access.redhat.com / errata/RHSA-2023:5454
Third Party Advisory
access.redhat.com / errata/RHSA-2023:5455
Third Party Advisory
access.redhat.com / errata/RHSA-2023:5476
Third Party Advisory
access.redhat.com / errata/RHSA-2024:0033
Third Party Advisory
access.redhat.com / security/cve/CVE-2023-4911
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatch
qualys.com / 2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
ExploitThird Party Advisory
qualys.com / cve-2023-4911
Third Party Advisory