The following table lists the changes that have been made to the
CVE-2025-4802 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by 3ff69d7a-14f2-4f67-a097-88dee7810d18May. 16, 2025
Action Type Old Value New Value Added Description Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo). Added CWE CWE-426 Added Reference https://sourceware.org/bugzilla/show_bug.cgi?id=32976 Added Reference https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380e