CVE-2023-4911
Glibc: buffer overflow in ld.so leading to privilege escalation
- Published
- Oct 3, 2023
- Updated
- Jul 14, 2026
- Assigning CNA
- redhat
- Evidence observed
- Nov 21, 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Docker-based CVE-2023-4911 lab for analyzing glibc ld.so buffer overflow and developing a local privilege escalation exploit with GDB debugging.
Proof of concept for CVE-2023-4911 (Looney Tunables) discovered by Qualys Threat Research Unit
Proof-of-concept exploit for CVE-2023-4911 (Looney Tunables), targeting a buffer overflow in glibc's GLIBC_TUNABLES parsing. Includes vulnerability detection and a compiled exploit for privilege escalation.
Pure C exploit for CVE-2023-4911 (Looney Tunables) — x86_64 & aarch64 implementations. Multi-processing brute-forcing, dynamic calibration, integrated ELF parser.
Proof-of-concept exploit for CVE-2023-4911 (Looney Tunables) targeting glibc privilege escalation on Linux systems. Includes vulnerability check and automated exploitation via Makefile.
Proof-of-concept exploit for CVE-2023-4911 (Looney Tunables), targeting a buffer overflow in glibc's GLIBC_TUNABLES parsing function for privilege escalation on Ubuntu 22.04.
Proof-of-concept exploit for CVE-2023-4911 (Looney Tunables) targeting glibc ld.so for local privilege escalation on Ubuntu 22.10. Implements heap shaping and stack spray techniques.
CVE-2023-4911 proof of concept
CVE-2023-4911
C-based proof-of-concept exploit for CVE-2023-4911, a local privilege escalation vulnerability in glibc ld.so. Includes Docker build and run instructions for testing.
Exploit tool for CVE-2023-4911, targeting the 'Looney Tunables' glibc vulnerability in various Linux distributions.
Python-based proof-of-concept exploit for CVE-2023-4911 (Looney Tunables) targeting glibc dynamic loader's parse_tunables() for local privilege escalation via the su binary.
Repository containing a Proof of Concept (PoC) demonstrating the impact of CVE-2023-4911, a vulnerability in glibc's ld.so dynamic loader, exposing risks related to Looney Tunables.
Exploit for CVE-2023-4911, a privilege escalation vulnerability in GNU C Library's dynamic loader, demonstrating buffer overflow exploitation.
CVE-2023-4911 (Looney Tunables) analysis report and Docker reproduction lab
CVE-2023-4911-Looney-Tunables
https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
CVE-2023-4911
PoC of CVE-2023-4911
Looney Tunables CVE-2023-4911
CVE-2026-63030 / CVE-2026-60137 - WordPress pre-auth RCE scanner
Beatriz Fresno Naumova · linux · Feb 11, 2026
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.