Untriaged
Glibc: buffer overflow in ld.so leading to privilege escalation
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Affected products
glibc
- *
- <2.39
compat-glibc
redhat-virtualization-host
- *
redhat-release-virtualization-host
- *
Matching in nixpkgs
pkgs.libc
GNU C Library
-
nixos-unstable -
- nixpkgs-unstable 2.40-66
pkgs.glibc
GNU C Library
-
nixos-unstable -
- nixpkgs-unstable 2.40-66
pkgs.getent
None
-
nixos-unstable -
- nixpkgs-unstable 2.40-66
pkgs.locale
None
-
nixos-unstable -
- nixpkgs-unstable 2.40-66
pkgs.mtrace
Perl script used to interpret and provide human readable output of the trace log contained in the file mtracedata, whose contents were produced by mtrace(3)
-
nixos-unstable -
- nixpkgs-unstable 2.40-66
pkgs.getconf
None
-
nixos-unstable -
- nixpkgs-unstable 2.40-66
pkgs.libiconv
None
-
nixos-unstable -
- nixpkgs-unstable 2.40
pkgs.glibcInfo
GNU Info manual of the GNU C Library
-
nixos-unstable -
- nixpkgs-unstable 2.40-66
pkgs.glibc_multi
None
-
nixos-unstable -
- nixpkgs-unstable 2.40-66
pkgs.glibcLocales
Locale information for the GNU C Library
-
nixos-unstable -
- nixpkgs-unstable 2.40-66
pkgs.glibc_memusage
GNU C Library
-
nixos-unstable -
- nixpkgs-unstable 2.40-66
pkgs.glibcLocalesUtf8
Locale information for the GNU C Library
-
nixos-unstable -
- nixpkgs-unstable 2.40-66
pkgs.unixtools.getent
None
-
nixos-unstable -
- nixpkgs-unstable 2.40-66
pkgs.unixtools.locale
None
-
nixos-unstable -
- nixpkgs-unstable 2.40-66
pkgs.unixtools.getconf
None
-
nixos-unstable -
- nixpkgs-unstable 2.40-66
pkgs.tests.hardeningFlags-clang.glibcxxassertionsStdenvUnsupp
None
pkgs.tests.hardeningFlags-gcc.glibcxxassertionsExplicitEnabled
None
pkgs.tests.hardeningFlags-gcc.glibcxxassertionsExplicitDisabled
None
pkgs.tests.hardeningFlags-clang.glibcxxassertionsExplicitEnabled
None
Package maintainers
-
@Ma27 Maximilian Bosch <maximilian@mbosch.me>
-
@ConnorBaker Connor Baker <ConnorBaker01@gmail.com>