CVE-2023-4911
published 2023-10-03CVE-2023-4911: A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a…
PriorityP192high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2023-12-12
Exploited in the wild
EPSS
81.42%
99.6th percentile
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Affected
79 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | glibc | < glibc 2.36-9+deb12u3 (bookworm) | glibc 2.36-9+deb12u3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | glibc | >= 0 < 2.31-13+deb11u7 | 2.31-13+deb11u7 |
| gnu | glibc | >= 0 < 2.36-9+deb12u3 | 2.36-9+deb12u3 |
| gnu | glibc | >= 0 < 2.37-12 | 2.37-12 |
| gnu | glibc | >= 0 < 2.37-12 | 2.37-12 |
| gnu | glibc | >= 0 < 2.35-0ubuntu3.4 | 2.35-0ubuntu3.4 |
| gnu | glibc | >= 2.34 < 2.39 | 2.39 |
| msrc | azl3_glibc_2.38-10_on_azure_linux_3.0 | — | — |
| msrc | azl3_glibc_2.38-6_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_glibc_2.35-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | codeready_linux_builder | — | — |
| redhat | codeready_linux_builder_eus | — | — |
| redhat | codeready_linux_builder_eus | — | — |
| redhat | codeready_linux_builder_eus | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for manipulation of the GLIBC_TUNABLES environment variable when SUID binaries are launched, as this is the direct exploitation vector for CVE-2023-4911. ↗
- →Alert on writes to /etc/ld.so.preload, which is used by Kinsing to load its rootkit for persistence after exploiting CVE-2023-4911. ↗
- →Monitor crontab modifications for entries that download and execute scripts every minute, a persistence mechanism used by Kinsing post-exploitation. ↗
- →CVE-2023-4911 affects default installations of Debian 12/13, Ubuntu 22.04/23.04, and Fedora 37/38; prioritize detection and patching on these platforms. ↗
- →Alpine Linux (musl libc) is NOT affected by CVE-2023-4911; focus detection efforts on glibc-based distributions only. ↗
- →Kinsing exploits CVE-2023-4911 to steal cloud service provider (CSP) credentials; monitor for credential access activity on cloud-hosted Linux systems. ↗
- ·The vulnerability was introduced in glibc in April 2021; systems running glibc versions predating this are not affected. ↗
- ·Exploitation requires local access and the ability to set environment variables for SUID binaries; remote exploitation is not directly possible without a prior foothold. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU Family
cisa_ics·2025-06-12
Siemens SIMATIC S7-1500 CPU Family
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU Family
Release DateJune 12, 2025
Alert CodeICSA-25-162-05
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU family
- Vulnerabilities: Missing Encryption of Sensitive Data, Out-of-bounds Read, Use After Free, Stack-
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (glibc) — CVE-2023-4911
vendor_oracle·2024-01-15·CVSS 7.8
CVE-2023-4911 [HIGH] Oracle Oracle Communications Risk Matrix: Signaling (glibc) — CVE-2023-4911
Oracle Oracle Communications Risk Matrix: Signaling (glibc) vulnerability
CVE: CVE-2023-4911
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2024 (JAN 2024)
CISA
GNU C Library Buffer Overflow Vulnerability
cisa·2023-11-21·CVSS 7.8
CVE-2023-4911 [HIGH] CWE-122 GNU C Library Buffer Overflow Vulnerability
Vulnerability: GNU C Library Buffer Overflow Vulnerability
Affected: GNU GNU C Library
GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa, https://access.redhat.com/security/cve/cve-2023-491
Microsoft
Glibc: buffer overflow in ld.so leading to privilege escalation
vendor_msrc·2023-10-10·CVSS 7.8
CVE-2023-4911 [HIGH] CWE-787 Glibc: buffer overflow in ld.so leading to privilege escalation
Glibc: buffer overflow in ld.so leading to privilege escalation
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: htt
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2023-10-03·CVSS 6.5
CVE-2023-4911 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
It was discovered that the GNU C Library incorrectly handled the
GLIBC_TUNABLES environment variable. An attacker could possibly use this
issue to perform a privilege escalation attack. (CVE-2023-4911)
It was discovered that the GNU C Library incorrectly handled certain DNS
responses when the system was configured in no-aaaa mode. A remote attacker
could possibly use this issue to cause the GNU C Library to crash,
resulting in a denial of service. This issue only affected Ubuntu 23.04.
(CVE-2023-4527)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
glibc: buffer overflow in ld.so leading to privilege escalation
vendor_redhat·2023-10-03·CVSS 7.8
CVE-2023-4911 [HIGH] CWE-122 glibc: buffer overflow in ld.so leading to privilege escalation
glibc: buffer overflow in ld.so leading to privilege escalation
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Statement: This vulnerability was introduced in glibc version 2.34. RHEL-8 ships
Debian
CVE-2023-4911: glibc - A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so whi...
vendor_debian·2023·CVSS 7.8
CVE-2023-4911 [HIGH] CVE-2023-4911: glibc - A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so whi...
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Scope: local
bookworm: resolved (fixed in 2.36-9+deb12u3)
bullseye: resolved (fixed in 2.31-13+deb11u7)
forky: resolved (fixed in 2.37-12)
sid: resolved (fixed in 2.37-12)
trixie: resolved (fixed in 2.37-12)
GHSA
GHSA-m77w-6vjw-wh2f: A buffer overflow was discovered in the GNU C Library's dynamic loader ld
ghsa_unreviewed·2023-10-03
CVE-2023-4911 [HIGH] CWE-122 GHSA-m77w-6vjw-wh2f: A buffer overflow was discovered in the GNU C Library's dynamic loader ld
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
OSV
CVE-2023-4911: A buffer overflow was discovered in the GNU C Library's dynamic loader ld
osv·2023-10-03·CVSS 7.8
CVE-2023-4911 [HIGH] CVE-2023-4911: A buffer overflow was discovered in the GNU C Library's dynamic loader ld
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
OSV
glibc vulnerabilities
osv·2023-10-03·CVSS 6.5
CVE-2023-4911 [MEDIUM] glibc vulnerabilities
glibc vulnerabilities
It was discovered that the GNU C Library incorrectly handled the
GLIBC_TUNABLES environment variable. An attacker could possibly use this
issue to perform a privilege escalation attack. (CVE-2023-4911)
It was discovered that the GNU C Library incorrectly handled certain DNS
responses when the system was configured in no-aaaa mode. A remote attacker
could possibly use this issue to cause the GNU C Library to crash,
resulting in a denial of service. This issue only affected Ubuntu 23.04.
(CVE-2023-4527)
VulnCheck
GNU C Library Buffer Overflow Vulnerability
vulncheck·2023·CVSS 7.8
CVE-2023-4911 [HIGH] CWE-122 GNU C Library Buffer Overflow Vulnerability
GNU C Library Buffer Overflow Vulnerability
GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges.
Affected: GNU GNU C Library (glibc)
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://blog.aquasec.com/loony-tunables-vulnerability-exploited-by-kinsing; https://www.trendmicro.com/en_us/research/23/k/cve-2023-46604-exploited-by-kinsing.html; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.sentinelone.com/resources/watchtower-end-of-year-report-2023/;
Exploit-DB
glibc 2.38 - Buffer Overflow
exploitdb·2026-02-11·CVSS 7.8
CVE-2023-4911 [HIGH] glibc 2.38 - Buffer Overflow
glibc 2.38 - Buffer Overflow
---
# Exploit Title: glibc 2.38 - Buffer Overflow
# Google Dork: N/A
# Date: 2025-10-08
# Exploit Author: Beatriz Fresno Naumova
# Vendor Homepage: https://www.gnu.org/software/libc/
# Software Link: https://ftp.gnu.org/gnu/libc/glibc-2.35.tar.gz
# Version: glibc 2.35 (specifically 2.35-0ubuntu3.3 on Ubuntu 22.04.3 LTS)
# Tested on: Ubuntu 22.04.3 LTS (glibc 2.35-0ubuntu3.3)
# CVE : CVE-2023-4911
# Description:
Looney Tunables - glibc GLIBC_TUNABLES Environment Variable Buffer Overflow
# This is a local privilege escalation exploit for CVE-2023-4911, also known as
# "Looney Tunables", caused by a buffer overflow in the glibc dynamic loader's
# environment variable parsing logic. The vulnerability is triggered by crafting
# a maliciously long GLIBC_TUNABLES s
Metasploit
Glibc Tunables Privilege Escalation CVE-2023-4911 (aka Looney Tunables)
metasploit·CVSS 7.8
CVE-2023-4911 [HIGH] Glibc Tunables Privilege Escalation CVE-2023-4911 (aka Looney Tunables)
Glibc Tunables Privilege Escalation CVE-2023-4911 (aka Looney Tunables)
A buffer overflow exists in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue allows an local attacker to use maliciously crafted GLIBC_TUNABLES when launching binaries with SUID permission to execute code in the context of the root user. This module targets glibc packaged on Ubuntu and Debian. The specific glibc versions this module targets are: Ubuntu: 2.35-0ubuntu3.4 > 2.35 2.37-0ubuntu2.1 > 2.37 2.38-1ubuntu6 > 2.38 Debian: 2.31-13-deb11u7 > 2.31 2.36-9-deb12u3 > 2.36 Fedora 37 and 38 and other distributions of linux also come packaged with versions of glibc vulnerable to CVE-2023-4911 however this module does not target them.
Nuclei
Looney Tunables Linux - Local Privilege Escalation
nuclei·CVSS 7.8
CVE-2023-4911 [HIGH] Looney Tunables Linux - Local Privilege Escalation
Looney Tunables Linux - Local Privilege Escalation
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
Template:
id: CVE-2023-4911
info:
name: Looney Tunables Linux - Local Privilege Escalation
author: nybble04
severity: high
description: |
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permissi
Securelist
What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant
blogs_securelist·2026-05-29
CVE-2025-55182 What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant
Yaroslav Shmelev
Anton Kivva
Denis Parinov
Vladimir Kuskov
Yanina Balandyuk-Opalinskaya
Table of Contents
Introduction
Software vulnerabilities and compromise of update sources
Configuration vulnerabilities
Insecure handling of credentials
Use of default passwords
Passing passwords via command arguments
Privilege escalation in the container
Attacks on sudo
Insecure file permissions
Lack of integrity checks
Conclusion
Authors
Yaroslav Shmelev
Anton Kivva
Denis Parinov
Vladimir Kuskov
Yanina Balandyuk-Opalinskaya
## Introduction
Containerization using Docker has become firmly established in modern development standards, significantly increasing the speed and convenience of deploying various services. Developers often use ready-made Docker images, making only minimal c
Qualys
Mutagen Astronomy: From Discovery to CISA Recognition—A Seven-Year Journey
blogs_qualys·2026-02-02·CVSS 7.8
CVE-2018-14634 [HIGH] Mutagen Astronomy: From Discovery to CISA Recognition—A Seven-Year Journey
## Table of Contents
Introduction
Why This Matters Now
Looking Back: The Original Discovery
Guidance for Security Teams
A Note on Our Research Mission
Conclusion
Frequently Asked Questions (FAQs)
## Introduction
On January 26, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2018-14634 to its Known Exploited Vulnerabilities (KEV) catalog . The same vulnerability was discovered by the Qualys Threat Research Unit (TRU) in September 2018.
We nicknamed it “Mutagen Astronomy” as a tribute to the 1992 film Sneakers . In that movie, the phrase “Setec Astronomy” is revealed as an anagram for “Too Many Secrets.” Following that tradition, “Mutagen Astronomy” is our anagram for “Too Many Arguments”, which precisely captures the technical root cause of this vulnera
Qualys
Mutagen Astronomy: A Linux Vulnerability’s Path to CISA KEV | Qualys
blogs_qualys·2026-02-02·CVSS 7.8
CVE-2018-14634 [HIGH] Mutagen Astronomy: A Linux Vulnerability’s Path to CISA KEV | Qualys
#### Table of Contents
- Introduction
- Why This Matters Now
- Looking Back: The Original Discovery
- Guidance for Security Teams
- A Note on Our Research Mission
- Conclusion
- Frequently Asked Questions (FAQs)
## Introduction
On January 26, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2018-14634 to its Known Exploited Vulnerabilities (KEV) catalog. The same vulnerability was discovered by the Qualys Threat Research Unit (TRU) in September 2018.
We nicknamed it “Mutagen Astronomy” as a tribute to the 1992 film Sneakers. In that movie, the phrase “Setec Astronomy” is revealed as an anagram for “Too Many Secrets.” Following that tradition, “Mutagen Astronomy” is our anagram for “Too Many Arguments”, which precisely captures the technical root cause of this
Securelist
Exploits and vulnerabilities in Q3 2024
blogs_securelist·2024-12-06·CVSS 8.1
CVE-2024-47177 [HIGH] Exploits and vulnerabilities in Q3 2024
Table of Contents
Statistics on registered vulnerabilities
Exploitation statistics
Windows and Linux vulnerability exploitation
Most prevalent exploits
Vulnerability exploitation in APT attacks
Interesting vulnerabilities
CVE-2024-47177 (CUPS filters)
CVE-2024-38112 (MSHTML Spoofing)
CVE-2024-6387 (regreSSHion)
CVE-2024-3183 (Free IPA)
CVE-2024-45519 (Zimbra)
CVE-2024-5290 (Ubuntu wpa_supplicant)
Conclusion and advice
Authors
Alexander Kolesnikov
Q3 2024 saw multiple vulnerabilities discovered in Windows and Linux subsystems that are not standard for cyberattacks. This is because operating system developers have been releasing new security mitigations for whole sets of vulnerabilities in commonly used subsystems. For example, a log integrity check is set to appear in the Co
Securelist
Analyzing the vulnerability landscape in Q3 2024
blogs_securelist·2024-12-06·CVSS 8.1
CVE-2024-47177 [HIGH] Analyzing the vulnerability landscape in Q3 2024
Table of Contents
- Statistics on registered vulnerabilities
- Exploitation statistics
- Vulnerability exploitation in APT attacks
- Interesting vulnerabilities
- CVE-2024-47177 (CUPS filters)
- CVE-2024-38112 (MSHTML Spoofing)
- CVE-2024-6387 (regreSSHion)
- CVE-2024-3183 (Free IPA)
- CVE-2024-45519 (Zimbra)
- CVE-2024-5290 (Ubuntu wpa_supplicant)
- Conclusion and advice
Authors
- Alexander Kolesnikov
Q3 2024 saw multiple vulnerabilities discovered in Windows and Linux subsystems that are not standard for cyberattacks. This is because operating system developers have been releasing new security mitigations for whole sets of vulnerabilities in commonly used subsystems. For example, a log integrity check is set to appear in the Common Log Filing System (CLFS) in Windows, so the number
Bleepingcomputer
New Linux glibc flaw lets attackers get root on major distros
blogs_bleepingcomputer·2024-01-30·CVSS 8.4
[HIGH] New Linux glibc flaw lets attackers get root on major distros
## New Linux glibc flaw lets attackers get root on major distros
## Sergiu Gatlan
"The buffer overflow issue poses a significant threat as it could allow local privilege escalation, enabling an unprivileged user to gain full root access through crafted inputs to applications that employ these logging functions," Qualys security researchers said.
"Although the vulnerability requires specific conditions to be exploited (such as an unusually long argv[0] or openlog() ident argument), its impact is significant due to the widespread use of the affected library."
## Impacts Debian, Ubuntu, and Fedora systems
While testing their findings, Qualys confirmed that Debian 12 and 13, Ubuntu 23.04 and 23.10, and Fedora 37 to 39 were all vulnerable to CVE-2023-6246 exploits, allowing any unprivilege
Trendmicro
Missbrauch von Apache ActiveMQ mit bösen Folgen
blogs_trendmicro·2023-11-23·CVSS 10.0
CVE-2023-46604 [CRITICAL] Missbrauch von Apache ActiveMQ mit bösen Folgen
Ausnutzung von Schwachstellen
## Missbrauch von Apache ActiveMQ mit bösen Folgen
Angreifer nutzen die Apache ActiveMQ Schwachstelle CVE-2023-46604 dazu aus, um Linux-Systeme mit Kinsing und weiterer Malware zu infizieren. Wir zeigen, wie das funktioniert und was dagegen zu tun ist.
By: Peter Girnus Nov 23, 2023 Read time: ( words)
Save to Folio
Wir haben festgestellt, dass die Apache ActiveMQ-Schwachstelle ( CVE-2023-46604 ) aktiv ausgenutzt wird, um Linux-Systeme mit der Kinsing -Malware (auch bekannt als h2miner) und dem entsprechenden Kryptowährungs-Miner zu infizieren.
Seit Anfang November sind mehrere Berichte über aktive Angriffe aufgetaucht. Diese Berichte beziehen sich auf Bedrohungsakteure, die CVE-2023-46604 ausnutzen (z. B. diejenigen, die hinter der HelloKitty-Ransomware-
Trendmicro
CVE-2023-46604 (Apache ActiveMQ) Vulnerability Exploited to Infect Systems With Cryptominers and Rootkits
blogs_trendmicro·2023-11-20·CVSS 10.0
CVE-2023-46604 [CRITICAL] CVE-2023-46604 (Apache ActiveMQ) Vulnerability Exploited to Infect Systems With Cryptominers and Rootkits
Exploits & Vulnerabilities
## CVE-2023-46604 (Apache ActiveMQ) Exploited to Infect Systems With Cryptominers and Rootkits
We uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner.
By: Peter Girnus 2023/11/20 Read time: ( words)
Save to Folio
We uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner. When exploited, this vulnerability leads to remote code execution (RCE), which Kinsing uses to download and install malware. The vulnerability itself is due to OpenWire commands failing to validate throwable c
Trendmicro
CVE-2023-46604 (Apache ActiveMQ) Vulnerability Exploited to Infect Systems With Cryptominers and Rootkits
blogs_trendmicro·2023-11-20·CVSS 10.0
CVE-2023-46604 [CRITICAL] CVE-2023-46604 (Apache ActiveMQ) Vulnerability Exploited to Infect Systems With Cryptominers and Rootkits
Exploits & Vulnerabilities
# CVE-2023-46604 (Apache ActiveMQ) Exploited to Infect Systems With Cryptominers and Rootkits
We uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner.
By: Peter Girnus
2023/11/20
Read time: ( words)
Save to Folio
We uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner. When exploited, this vulnerability leads to remote code execution (RCE), which Kinsing uses to download and install malware. The vulnerability itself is due to OpenWire commands failing to validate throwable c
Trendmicro
CVE-2023-46604 (Apache ActiveMQ) Vulnerability Exploited to Infect Systems With Cryptominers and Rootkits
blogs_trendmicro·2023-11-20·CVSS 10.0
CVE-2023-46604 [CRITICAL] CVE-2023-46604 (Apache ActiveMQ) Vulnerability Exploited to Infect Systems With Cryptominers and Rootkits
Exploits y vulnerabilidades
## CVE-2023-46604 (Apache ActiveMQ) Exploited to Infect Systems With Cryptominers and Rootkits
We uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner.
By: Peter Girnus Nov 20, 2023 Read time: ( words)
Save to Folio
We uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner. When exploited, this vulnerability leads to remote code execution (RCE), which Kinsing uses to download and install malware. The vulnerability itself is due to OpenWire commands failing to validate throwabl
Trendmicro
CVE-2023-46604 (Apache ActiveMQ) Vulnerability Exploited to Infect Systems With Cryptominers and Rootkits
blogs_trendmicro·2023-11-20·CVSS 10.0
CVE-2023-46604 [CRITICAL] CVE-2023-46604 (Apache ActiveMQ) Vulnerability Exploited to Infect Systems With Cryptominers and Rootkits
Exploits & Vulnerabilities
## CVE-2023-46604 (Apache ActiveMQ) Exploited to Infect Systems With Cryptominers and Rootkits
We uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner.
By: Peter Girnus Nov 20, 2023 Read time: ( words)
Save to Folio
We uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner. When exploited, this vulnerability leads to remote code execution (RCE), which Kinsing uses to download and install malware. The vulnerability itself is due to OpenWire commands failing to validate throwable
Trendmicro
CVE-2023-46604 (Apache ActiveMQ) Vulnerability Exploited to Infect Systems With Cryptominers and Rootkits
blogs_trendmicro·2023-11-20·CVSS 10.0
CVE-2023-46604 [CRITICAL] CVE-2023-46604 (Apache ActiveMQ) Vulnerability Exploited to Infect Systems With Cryptominers and Rootkits
Sfruttamento vulnerabilità
## CVE-2023-46604 (Apache ActiveMQ) Exploited to Infect Systems With Cryptominers and Rootkits
We uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner.
By: Peter Girnus Nov 20, 2023 Read time: ( words)
Save to Folio
We uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner. When exploited, this vulnerability leads to remote code execution (RCE), which Kinsing uses to download and install malware. The vulnerability itself is due to OpenWire commands failing to validate throwable
Bleepingcomputer
GNOME Linux systems exposed to RCE attacks via file downloads
blogs_bleepingcomputer·2023-10-09·CVSS 8.8
CVE-2023-43641 [HIGH] GNOME Linux systems exposed to RCE attacks via file downloads
## GNOME Linux systems exposed to RCE attacks via file downloads
## Sergiu Gatlan
GNOME is a widely used desktop environment across various Linux distributions such as Debian, Ubuntu, Fedora, Red Hat Enterprise, and SUSE Linux Enterprise.
Attackers can successfully exploit the flaw in question (CVE-2023-43641) to execute malicious code by taking advantage of Tracker Miners automatically indexing all downloaded files to update the search index on GNOME Linux devices.
"Due to the way that it's used by tracker-miners, this vulnerability in libcue became a 1-click RCE. If you use GNOME, please update today," said GitHub security researcher Kevin Backhouse , who found the bug.
In order to exploit this vulnerability, the targeted user must download a maliciously crafted .CUE file, which is
Bleepingcomputer
Exploits released for Linux flaw giving root on major distros
blogs_bleepingcomputer·2023-10-05·CVSS 7.8
CVE-2023-4911 [HIGH] Exploits released for Linux flaw giving root on major distros
## Exploits released for Linux flaw giving root on major distros
## Sergiu Gatlan
Proof-of-concept exploits have already surfaced online for a high-severity flaw in GNU C Library's dynamic loader, allowing local attackers to gain root privileges on major Linux distributions.
Dubbed ' Looney Tunables' and tracked as CVE-2023-4911 , this security vulnerability is due to a buffer overflow weakness, and it affects default installations of Debian 12 and 13, Ubuntu 22.04 and 23.04, and Fedora 37 and 38.
Attackers can trigger it using a maliciously crafted GLIBC_TUNABLES environment variable processed by the ld.so dynamic loader to gain arbitrary code execution with root privileges when launching binaries with SUID permission.
Since Qualys' Threat Research Unit disclosed it on Tuesday, sever
Qualys
CVE-2023-4911: Local Privilege Escalation in glibc’s ld.so | Qualys
blogs_qualys·2023-10-03·CVSS 7.8
CVE-2023-4911 [HIGH] CVE-2023-4911: Local Privilege Escalation in glibc’s ld.so | Qualys
#### Table of Contents
- About GNU C Librarys dynamic loader
- Potential Impact of Looney Tunables
- Disclosure Timeline
- Technical Details
- Qualys QID Coverage
- Conclusion
The Qualys Threat Research Unit (TRU) has discovered a buffer overflow vulnerability in GNU C Library’s dynamic loader’s processing of the GLIBC_TUNABLES environment variable. We have successfully identified and exploited this vulnerability (a local privilege escalation that grants full root privileges) on the default installations of Fedora 37 and 38, Ubuntu 22.04 and 23.04, and Debian 12 and 13. It’s likely that other distributions are similarly susceptible, although we’ve noted that Alpine Linux remains an exception due to its use of musl libc instead of glibc. This vulnerability was introduced in April 2021.
C
Qualys
CVE-2023-4911: Looney Tunables – Local Privilege Escalation in the glibc’s ld.so
blogs_qualys·2023-10-03·CVSS 7.8
[HIGH] CVE-2023-4911: Looney Tunables – Local Privilege Escalation in the glibc’s ld.so
## Table of Contents
About GNU C Librarys dynamic loader
Potential Impact of Looney Tunables
Disclosure Timeline
Technical Details
Qualys QID Coverage
Conclusion
The Qualys Threat Research Unit (TRU) has discovered a buffer overflow vulnerability in GNU C Library’s dynamic loader’s processing of the GLIBC_TUNABLES environment variable. We have successfully identified and exploited this vulnerability (a local privilege escalation that grants full root privileges) on the default installations of Fedora 37 and 38, Ubuntu 22.04 and 23.04, and Debian 12 and 13. It’s likely that other distributions are similarly susceptible, although we’ve noted that Alpine Linux remains an exception due to its use of musl libc instead of glibc. This vulnerability was introduced in April 2021.
Considerin
Bugzilla
CVE-2023-4911 glibc: buffer overflow in ld.so leading to privilege escalation
bugzilla·2023-09-11·CVSS 7.8
CVE-2023-4911 [HIGH] CVE-2023-4911 glibc: buffer overflow in ld.so leading to privilege escalation
CVE-2023-4911 glibc: buffer overflow in ld.so leading to privilege escalation
Researchers discovered a vulnerability in the GNU C Library's dynamic loader (ld.so). This vulnerability was introduced in April 2021 (glibc 2.34) by the following commit: https://sourceware.org/git?p=glibc.git;a=commit;h=2ed18c5b534d9e92fc006202a5af0df6b72e7aca
Per researchers this vulnerability is exploitable by any local user and can lead to privilege escalation when combined with almost any SUID-root binaries.
Discussion:
Upstream commit is https://sourceware.org/git/?p=glibc.git;a=commit;h=1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa
---
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 2241966]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.0
arXiv
Distilling Lightweight Language Models for C/C++ Vulnerabilities
arxiv_fulltext·2025-10-08
Distilling Lightweight Language Models for C/C++ Vulnerabilities
## Abstract
The increasing complexity of modern software systems exacerbates the prevalence of security vulnerabilities, posing risks of severe breaches and substantial economic loss. Consequently, robust code vulnerability detection is essential for software security. While Large Language Models (LLMs) have demonstrated remarkable capabilities in natural language processing, their potential for automated code vulnerability detection remains underexplored. This paper presents FineSec, a novel framework that harnesses LLMs through knowledge distillation to enable efficient and precise vulnerability identification in C/C++ codebases. FineSec utilizes knowledge distillation to transfer expertise from large teacher models to compact student models, achieving high accuracy with minimal computa
https://access.redhat.com/errata/RHSA-2023:5453https://access.redhat.com/errata/RHSA-2023:5454https://access.redhat.com/errata/RHSA-2023:5455https://access.redhat.com/errata/RHSA-2023:5476https://access.redhat.com/errata/RHSA-2024:0033https://access.redhat.com/security/cve/CVE-2023-4911https://bugzilla.redhat.com/show_bug.cgi?id=2238352https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txthttps://www.qualys.com/cve-2023-4911/http://packetstormsecurity.com/files/174986/glibc-ld.so-Local-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/176288/Glibc-Tunables-Privilege-Escalation.htmlhttp://seclists.org/fulldisclosure/2023/Oct/11http://www.openwall.com/lists/oss-security/2023/10/03/2http://www.openwall.com/lists/oss-security/2023/10/03/3http://www.openwall.com/lists/oss-security/2023/10/05/1http://www.openwall.com/lists/oss-security/2023/10/13/11http://www.openwall.com/lists/oss-security/2023/10/14/3http://www.openwall.com/lists/oss-security/2023/10/14/5http://www.openwall.com/lists/oss-security/2023/10/14/6https://access.redhat.com/errata/RHSA-2023:5453https://access.redhat.com/errata/RHSA-2023:5454https://access.redhat.com/errata/RHSA-2023:5455https://access.redhat.com/errata/RHSA-2023:5476https://access.redhat.com/errata/RHSA-2024:0033https://access.redhat.com/security/cve/CVE-2023-4911https://bugzilla.redhat.com/show_bug.cgi?id=2238352https://lists.fedoraproject.org/archives/list/[email protected]/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/https://lists.fedoraproject.org/archives/list/[email protected]/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/https://lists.fedoraproject.org/archives/list/[email protected]/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/https://security.gentoo.org/glsa/202310-03https://security.netapp.com/advisory/ntap-20231013-0006/https://www.debian.org/security/2023/dsa-5514https://www.exploit-db.com/exploits/52479https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txthttps://www.qualys.com/cve-2023-4911/https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-794697.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-831302.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4911
2023-10-03
Published
2023-11-21
Added to CISA KEV
Exploited in the wild