Looney Tunables: New Linux Flaw Enables Privilege Escalation on Major Distributions

Post Reply
Shane1145
Posts: 1729
Joined: Wed Sep 25, 2024 2:31 pm

Looney Tunables: New Linux Flaw Enables Privilege Escalation on Major Distributions

Post by Shane1145 »

A new Linux security vulnerability dubbed Looney Tunables has been discovered in the GNU C library's ld.so dynamic loader that, if successfully exploited, could lead to a local privilege escalation and allow a threat actor to gain root privileges.

Tracked as CVE-2023-4911 (CVSS score: 7.8), the issue is a buffer overflow that resides in the dynamic loader's processing of the GLIBC_TUNABLES environment variable. Cybersecurity firm Qualys, which disclosed details of the bug, said it was introduced as part of a code commit made in April 2021.

https://thehackernews.com/2023/10/loone ... ables.html
Post Reply