Looney Tunables: New Linux Flaw Enables Privilege Escalation on Major Distributions

New Linux vulnerability (CVE-2023-4911) named Looney Tunables found in the GNU C library's dynamic loader. Exploitation could lead to root privileges.

The Hacker News
Looney Tunables: Schwachstelle in C-Bibliothek gefÀhrdet Linux-Systeme - Golem.de
https://www.golem.de/news/looney-tunables-schwachstelle-in-c-bibliothek-gefaehrdet-linux-systeme-2310-178180.html #LooneyTunables
Looney Tunables: Schwachstelle in C-Bibliothek gefÀhrdet Linux-Systeme - Golem.de

Eine PufferĂŒberlauf-Schwachstelle im dynamischen Lader von glibc ermöglicht es Angreifern, auf Linux-Systemen Root-Rechte zu erlangen.

Golem.de
Patch now: This serious Linux vulnerability affects nearly all distributions
🔗 https://tchlp.com/48KSErG
#linux #vulnerability #looneytunables
Patch now: This serious Linux vulnerability affects nearly all distributions

Qualys has discovered a nasty security hole, dubbed 'Looney Tunables', in the glibc C library. This means almost all Linux distributions have a bad security problem.

ZDNET
Multiple experts released exploits for Linux local privilege escalation flaw Looney Tunables

Researchers published PoC exploits for CVE-2023-4911 vulnerability impacting most popular Linux distributions.

Security Affairs
Looney Tunables, a new Linux vulnerability, exploits a weakness in the GNU C Library's dynamic loader https://www.fosslife.org/new-linux-vulnerability-affects-glibc #LooneyTunables #GNUCLibrary #Linux #vulnerability #security #FOSS

This week’s news about the "Looney Tunes flaw" highlighted a condition which can allow a local user to access root privileges from the command line. Part of the RL Security team's task is to have mitigation strategies ready for such cases - reporting vulnerabilities and suggesting fixes upstream, and also writing our own extra packages.

This week, the Security SIG has published our extra packages and formalized a wiki: https://rockylinux.org/news/security-sig-update/ #looneytunables #securityupdate #glibc

Special Interest Group Announcement - Security | Rocky Linux

Rocky Linux is an open enterprise Operating System designed to be 100% bug-for-bug compatible with Enterprise Linux.

New 'Looney Tunables' Linux bug gives root on major distros

A new Linux vulnerability known as 'Looney Tunables' enables local attackers to gain root privileges by exploiting a buffer overflow weakness in the GNU C Library's ld.so dynamic loader.

BleepingComputer
Looney Tunables, la Ășltima vulnerabilidad grave afecta a Ubuntu y la mayorĂ­a de distribuciones Linux

Looney Tunables es una greve vulnerabilidad que afecta a la mayorĂ­a de distribuciones basadas en el kernel Linux.

Ubunlog
New Linux Vulnerability Enables a Privilege Esc... » Linux Magazine

Looney Tunables is a new Linux vulnerability that has been discovered in the GNU C library that can lead to privilege escalation.

Linux Magazine
New "Looney Tunables" bug allows attackers to gain root access to major Linux distros due to a vulnerability found in the GLIBC_TUNABLES environment variable.

https://www.bleepingcomputer.com/news/security/new-looney-tunables-linux-bug-gives-root-on-major-distros/

#infosec #cybersecurity #Linux #LooneyTunables #vulnerability #CVE_2023_4911
New 'Looney Tunables' Linux bug gives root on major distros

A new Linux vulnerability known as 'Looney Tunables' enables local attackers to gain root privileges by exploiting a buffer overflow weakness in the GNU C Library's ld.so dynamic loader.

BleepingComputer