CVE-2025-4802
published 2025-05-16CVE-2025-4802: Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared…
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.55%
42.3th percentile
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.36-9+deb12u11 (bookworm) | glibc 2.36-9+deb12u11 (bookworm) |
| gnu | glibc | >= 0 < 2.31-13+deb11u13 | 2.31-13+deb11u13 |
| gnu | glibc | >= 0 < 2.36-9+deb12u11 | 2.36-9+deb12u11 |
| gnu | glibc | >= 0 < 2.39-4 | 2.39-4 |
| gnu | glibc | >= 0 < 2.39-4 | 2.39-4 |
| gnu | glibc | 2.27 – 2.38 | — |
| msrc | azl3_glibc_2.38-11_on_azure_linux_3.0 | — | — |
| msrc | azl3_glibc_2.38-12_on_azure_linux_3.0 | — | — |
| msrc | cbl2_glibc_2.35-10_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_glibc_2.35-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_glibc_2.35-9_on_cbl_mariner_2.0 | — | — |
| the_gnu_c_library | glibc | >= 2.27 < 2.39 | 2.39 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_msrc8.4HIGH
vendor_debian7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Install (FreeType) — CVE-2025-4802
vendor_oracle·2025-10-15·CVSS 7.8
CVE-2025-4802 [HIGH] Oracle Oracle Communications Risk Matrix: Install (FreeType) — CVE-2025-4802
Oracle Oracle Communications Risk Matrix: Install (FreeType) vulnerability
CVE: CVE-2025-4802
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2025 (OCT 2025)
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (glibc) — CVE-2025-4802
vendor_oracle·2025-07-15·CVSS 7.8
CVE-2025-4802 [HIGH] Oracle Oracle Communications Risk Matrix: Configuration (glibc) — CVE-2025-4802
Oracle Oracle Communications Risk Matrix: Configuration (glibc) vulnerability
CVE: CVE-2025-4802
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2025 (JUL 2025)
Ubuntu
GNU C Library vulnerability
vendor_ubuntu·2025-05-28
CVE-2025-4802 GNU C Library vulnerability
Title: GNU C Library vulnerability
Summary: GNU C Library could be made to crash or run programs if it processed
specially crafted dynamically shared library.
It was discovered that the GNU C Library incorrectly search LD_LIBRARY_PATH
to determine which library to load when statically linked setuid binary
calls dlopen. A local attacker could possibly use this issue to cause a
denial of service or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH
vendor_redhat·2025-05-16·CVSS 7.8
CVE-2025-4802 [HIGH] CWE-426 glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH
glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
A flaw was found in the glibc library. A statically linked setuid binary that calls dlopen(), including internal dlopen() calls after setlocale() or calls to NSS functions such as getaddrinfo(), may incorrectly search LD_LIBRARY_PATH to determine which library to load, allowing a local attacker to load malicious shared libraries, escalate privileges and execute arbitrary code.
Statement: This issue
Microsoft
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid bi
vendor_msrc·2025-05-13·CVSS 8.4
CVE-2025-4802 [HIGH] CWE-426 Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid bi
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in O
Debian
CVE-2025-4802: glibc - Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Librar...
vendor_debian·2025·CVSS 7.8
CVE-2025-4802 [HIGH] CVE-2025-4802: glibc - Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Librar...
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
Scope: local
bookworm: resolved (fixed in 2.36-9+deb12u11)
bullseye: resolved (fixed in 2.31-13+deb11u13)
forky: resolved (fixed in 2.39-4)
sid: resolved (fixed in 2.39-4)
trixie: resolved (fixed in 2.39-4)
GHSA
GHSA-8mm9-c4mg-vfjh: Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2
ghsa_unreviewed·2025-05-16
CVE-2025-4802 [CRITICAL] CWE-426 GHSA-8mm9-c4mg-vfjh: Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
OSV
CVE-2025-4802: Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2
osv·2025-05-16·CVSS 7.8
CVE-2025-4802 [HIGH] CVE-2025-4802: Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://sourceware.org/bugzilla/show_bug.cgi?id=32976https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380ehttp://www.openwall.com/lists/oss-security/2025/05/16/7http://www.openwall.com/lists/oss-security/2025/05/17/2https://lists.debian.org/debian-lts-announce/2025/05/msg00033.html
2025-05-16
Published