Cobra Forum

Plesk Panel => Others => Topic started by: senthil on Oct 17, 2025, 07:17 AM

Title: CVE-2023-4911: Vulnerability in glibc's ld.so
Post by: senthil on Oct 17, 2025, 07:17 AM
Situation

CVE-2023-4911 was discovered in glibc's ld.so.

Impact

A buffer overflow was discovered in the GNU C Library's dynamic loader ld .so while processing the
GLIBC_TUNABLES environment variable (CVE-2023-4911 (https://www.cve.org/CVERecord?id=CVE-2023-4911v)). This issue could allow a local attacker to use
maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to
execute code with elevated privileges.

Call to action

The vulnerability affects the system library. Plesk doesn't ship its own glibc. So, it is fixed by the system
package's update.

OS vendor's advisories should be followed to update the vulnerable library.

These Linux distributions have already published fixes: