Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library...
Vulnerability Description
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-4802
Credits & Attribution
No credits recorded in the NVD database.
References
More from The GNU C Library
View All →Affected Vendor
The GNU C Library
View all reports →