CVE-2025-4802

Name
CVE-2025-4802
Description
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
3ff69d7a-14f2-4f67-a097-88dee7810d18 https://sourceware.org/bugzilla/show_bug.cgi?id=32976
3ff69d7a-14f2-4f67-a097-88dee7810d18 https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380e
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/05/16/7
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/05/17/2
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/05/msg00033.html

Match rules

CPE URI Source package Min version Max version
glibc >= 2.27 < 2.39

Vulnerable and fixed packages

Source package Branch Version Maintainer Status