Updated glibc packages fix a security vulnerability
Publication date: 11 Oct 2023Modification date: 11 Oct 2023
Type: security
Affected Mageia releases : 8 , 9
CVE: CVE-2023-4911
Description
The updated packages fix a security vulnerability:
A buffer overflow was discovered in the GNU C Library's dynamic loader
ld.so while processing the GLIBC_TUNABLES environment variable. This
issue could allow a local attacker to use maliciously crafted
GLIBC_TUNABLES environment variables when launching binaries with SUID
permission to execute code with elevated privileges. (CVE-2023-4911)
References
SRPMS
8/core
- glibc-2.32-32.mga8
9/core
- glibc-2.36-51.mga9