The GNU C Library project provides the core libraries for the GNU system and GNU/Linux systems, as well as many other systems that use Linux as the kernel. These libraries provide critical APIs including ISO C11, POSIX.1-2008, BSD, OS-specific APIs and more. These APIs include such foundational facilities as open, read, write, malloc, printf, getaddrinfo, dlopen, pthread_create, crypt, login, exit and more.
Security Fix(es):
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBCTUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBCTUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.(CVE-2023-4911)
{ "severity": "High" }
{ "x86_64": [ "glibc-debuginfo-2.34-137.oe2203sp1.x86_64.rpm", "glibc-debugsource-2.34-137.oe2203sp1.x86_64.rpm", "glibc-2.34-137.oe2203sp1.x86_64.rpm", "glibc-all-langpacks-2.34-137.oe2203sp1.x86_64.rpm", "glibc-devel-2.34-137.oe2203sp1.x86_64.rpm", "nss_modules-2.34-137.oe2203sp1.x86_64.rpm", "nscd-2.34-137.oe2203sp1.x86_64.rpm", "glibc-nss-devel-2.34-137.oe2203sp1.x86_64.rpm", "glibc-locale-source-2.34-137.oe2203sp1.x86_64.rpm", "glibc-compat-2.17-2.34-137.oe2203sp1.x86_64.rpm", "glibc-common-2.34-137.oe2203sp1.x86_64.rpm", "libnsl-2.34-137.oe2203sp1.x86_64.rpm", "glibc-debugutils-2.34-137.oe2203sp1.x86_64.rpm", "glibc-locale-archive-2.34-137.oe2203sp1.x86_64.rpm" ], "src": [ "glibc-2.34-137.oe2203sp1.src.rpm" ], "noarch": [ "glibc-help-2.34-137.oe2203sp1.noarch.rpm" ], "aarch64": [ "glibc-locale-source-2.34-137.oe2203sp1.aarch64.rpm", "glibc-2.34-137.oe2203sp1.aarch64.rpm", "glibc-compat-2.17-2.34-137.oe2203sp1.aarch64.rpm", "glibc-locale-archive-2.34-137.oe2203sp1.aarch64.rpm", "glibc-all-langpacks-2.34-137.oe2203sp1.aarch64.rpm", "glibc-debugutils-2.34-137.oe2203sp1.aarch64.rpm", "glibc-common-2.34-137.oe2203sp1.aarch64.rpm", "nss_modules-2.34-137.oe2203sp1.aarch64.rpm", "glibc-debuginfo-2.34-137.oe2203sp1.aarch64.rpm", "libnsl-2.34-137.oe2203sp1.aarch64.rpm", "glibc-nss-devel-2.34-137.oe2203sp1.aarch64.rpm", "glibc-devel-2.34-137.oe2203sp1.aarch64.rpm", "glibc-debugsource-2.34-137.oe2203sp1.aarch64.rpm", "nscd-2.34-137.oe2203sp1.aarch64.rpm" ] }