Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 9: 2025-0164 severe: glibc Untrusted LD_LIBRARY_PATH Issue

mageia
Calendar Grey May 24, 2025
Dist Mageia Esm H88
A critical LD_LIBRARY_PATH exploit in glibc affects Mageia, allowing malicious library loading by attackers.
An untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library versions 2.27 to 2.38 allows attacker-controlled loading of dynamically shared libraries in sta...

Summary

An untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library versions 2.27 to 2.38 allows attacker-controlled loading of dynamically shared libraries in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo). (CVE-2025-4802)

References

- https://bugs.mageia.org/show_bug.cgi?id=34286

- https://www.openwall.com/lists/oss-security/2025/05/16/7

- https://www.openwall.com/lists/oss-security/2025/05/17/2

- https://www.cve.org/CVERecord?id=CVE-2025-4802

Resolution

SRPMS

- 9/core/glibc-2.36-56.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 24 May 2025
URL: https://advisories.mageia.org/MGASA-2025-0164.html
Type: security
CVE: CVE-2025-4802

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here