Haavatavus Glibcis, mis mõjutab staatiliselt koostatud suid-failide dlopen

Glibc standard C library's vulnerability (CVE-2025-4802) allows code execution with privileges of another user, granted when running applications with the suid flag. The danger of the issue is negated by the conditions under which it manifests—Glibc developers could not find any suid programs to which the discovered vulnerability could be applied. However, it is possible that custom suid programs satisfying the conditions for an attack may be in use.

Exploitation of the vulnerability is only possible for statically linked suid programs that call the dlopen function. Aside from programs that directly invoke dlopen, the vulnerability also affects programs where the dlopen function is executed indirectly, as a result of calling setlocale or NSS functions such as getaddrinfo.

The issue is caused by the handling of the LD_LIBRARY_PATH environment variable in the context of suid applications when calling dlopen from statically linked programs (where LD_LIBRARY_PATH was ignored only in dynamic linking). By setting a path in LD_LIBRARY_PATH, an attacker can arrange to load a malicious library from their directory. The vulnerability has been present since Glibc version 2.27 (February 2018) and was fixed in Glibc version 2.39 (February 2024).

Allikas: opennet.ru

Osta usaldusväärne veebihosting DDoS kaitsega, VPS VDS serverid 🔥 Osta usaldusväärne veebihosting DDoS kaitsega, VPS VDS serverid | ProHoster