A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

Published: 2023-10-03

CVSS: 7.8

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Download CVE-2023-4911 POC (Proof-of-Concept) here:

Tip: Download official Tor Browser at https://www.torproject.org/download/ to access .onion links.

https://connollyfinan.ie/poc-628-cve-2024-4040/

https://connollyfinan.ie/poc-246-cve-2025-40778/

https://connollyfinan.ie/poc-462-cve-2018-16844/

https://connollyfinan.ie/poc-312-cve-2024-49138/

https://connollyfinan.ie/poc-540-cve-2023-22522/