A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBCTUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBCTUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
{ "priority_reason": "Local privilege escalation in a package that is installed on all Ubuntu instances.", "availability": "No subscription required", "binaries": [ { "binary_name": "glibc-doc", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "glibc-source", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc-bin", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc-bin-dbgsym", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc-dev-bin", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc-dev-bin-dbgsym", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc-devtools", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc-devtools-dbgsym", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6-amd64", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6-amd64-dbgsym", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6-dbg", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6-dev", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6-dev-amd64", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6-dev-i386", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6-dev-s390", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6-dev-x32", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6-i386", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6-i386-dbgsym", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6-prof", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6-s390", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6-s390-dbgsym", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6-x32", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "libc6-x32-dbgsym", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "locales", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "locales-all", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "nscd", "binary_version": "2.35-0ubuntu3.4" }, { "binary_name": "nscd-dbgsym", "binary_version": "2.35-0ubuntu3.4" } ] }
{ "priority_reason": "Local privilege escalation in a package that is installed on all Ubuntu instances.", "availability": "No subscription required", "binaries": [ { "binary_name": "glibc-doc", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "glibc-source", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc-bin", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc-bin-dbgsym", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc-dev-bin", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc-dev-bin-dbgsym", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc-devtools", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc-devtools-dbgsym", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-amd64", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-amd64-dbgsym", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-dbg", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-dev", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-dev-amd64", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-dev-dbgsym", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-dev-i386", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-dev-s390", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-dev-x32", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-i386", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-i386-dbgsym", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-prof", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-s390", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-s390-dbgsym", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-x32", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "libc6-x32-dbgsym", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "locales", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "locales-all", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "nscd", "binary_version": "2.38-1ubuntu6" }, { "binary_name": "nscd-dbgsym", "binary_version": "2.38-1ubuntu6" } ] }