GPU VulnDB

Database/Kernel, userspace & hypervisor

glibc (ld.so): Looney Tunables: buffer overflow in the ld.so GLIBC_TUNABLES parser - local root on default installs

CVE-2023-4911Kernel, userspace & hypervisorcurated

Impact

Looney Tunables: buffer overflow in the ld.so GLIBC_TUNABLES parser - local root on default installs; used by Kinsing cloud crypto-mining crews

Who can reach it

Local user, incl. any shell inside a container that shares the host glibc

What to do

Package update; every long-running process must be restarted to pick up the new loader, which in practice means a rolling node restart or reboot for full coverage

Fleet impact

How widespread

Universal - glibc is in essentially every base image and on every host; Qualys got root on default Fedora, Ubuntu 22.04/23.04 and Debian 12/13

Cost to remediate

node-drain for the host glibc (SUID binaries must be re-executed) plus a **rebuild of every container image** in the fleet - the pain is the image fan-out, not the host

Why it hits the whole fleet

Buffer overflow in GLIBC_TUNABLES parsing gives local root from any SUID binary, so it converts every low-privilege foothold - in a container or on the host - into root, across every image and host simultaneously

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.