CVE-2025-4802 – GNU C Library LD_LIBRARY_PATH Path Traversal Vulnerability

The following table lists the changes that have been made to the
CVE-2025-4802 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 3ff69d7a-14f2-4f67-a097-88dee7810d18

    May. 16, 2025

    Action Type Old Value New Value
    Added Description Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
    Added CWE CWE-426
    Added Reference https://sourceware.org/bugzilla/show_bug.cgi?id=32976
    Added Reference https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380e
Share the Post:

Related Posts