glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH
Published May 16, 2025
7.8
HIGHCVSS 3.1
EPSS 0.59%
Description
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
Affected products
-
- Version 2.27StatusaffectedConstraints<2.39
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The GNU C Library | Glibc | unaffected |
|
No data.
Red Hat Discovery 1.14
discovery/discovery-server-rhel9:1.14.5-1749654812
Fixed · RHSA-2025:9028
Red Hat Discovery 2
discovery/discovery-server-rhel9:2.0.0-1752592913
Fixed · RHSA-2025:11487
Red Hat Enterprise Linux 7 Extended Lifecycle Support
glibc-0:2.17-326.el7_9.5
Fixed · RHSA-2025:10219
Red Hat Enterprise Linux 7.7 Advanced Update Support
glibc-0:2.17-292.el7_7.3
Fixed · RHSA-2025:10220
Red Hat Enterprise Linux 8
glibc-0:2.28-251.el8_10.22
Fixed · RHSA-2025:8686
Red Hat Enterprise Linux 8
glibc-0:2.28-251.el8_10.22
Fixed · RHSA-2025:8686
Red Hat Enterprise Linux 9
glibc-0:2.34-168.el9_6.19
Fixed · RHSA-2025:8655
Red Hat Enterprise Linux 9
glibc-0:2.34-168.el9_6.19
Fixed · RHSA-2025:8655
Red Hat Enterprise Linux 9.4 Extended Update Support
glibc-0:2.34-100.el9_4.12
Fixed · RHSA-2025:9336
Red Hat OpenShift Container Platform 4.16
rhcos-416.94.202506251808-0
Fixed · RHSA-2025:9765
Red Hat OpenShift Container Platform 4.17
rhcos-417.94.202507021305-0
Fixed · RHSA-2025:10294
Red Hat OpenShift Container Platform 4.18
rhcos-418.94.202506251005-0
Fixed · RHSA-2025:9725
Red Hat OpenShift Container Platform 4.19
rhcos-4.19.9.6.202506252250-0
Fixed · RHSA-2025:9750
Red Hat Enterprise Linux 10
glibc
Not affected
Red Hat Enterprise Linux 6
compat-glibc
Not affected
Red Hat Enterprise Linux 6
glibc
Not affected
Red Hat Enterprise Linux 7
compat-glibc
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Discovery 1.14 | discovery/discovery-server-rhel9:1.14.5-1749654812 | Fixed | RHSA-2025:9028 |
| Red Hat Discovery 2 | discovery/discovery-server-rhel9:2.0.0-1752592913 | Fixed | RHSA-2025:11487 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | glibc-0:2.17-326.el7_9.5 | Fixed | RHSA-2025:10219 |
| Red Hat Enterprise Linux 7.7 Advanced Update Support | glibc-0:2.17-292.el7_7.3 | Fixed | RHSA-2025:10220 |
| Red Hat Enterprise Linux 8 | glibc-0:2.28-251.el8_10.22 | Fixed | RHSA-2025:8686 |
| Red Hat Enterprise Linux 8 | glibc-0:2.28-251.el8_10.22 | Fixed | RHSA-2025:8686 |
| Red Hat Enterprise Linux 9 | glibc-0:2.34-168.el9_6.19 | Fixed | RHSA-2025:8655 |
| Red Hat Enterprise Linux 9 | glibc-0:2.34-168.el9_6.19 | Fixed | RHSA-2025:8655 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | glibc-0:2.34-100.el9_4.12 | Fixed | RHSA-2025:9336 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202506251808-0 | Fixed | RHSA-2025:9765 |
| Red Hat OpenShift Container Platform 4.17 | rhcos-417.94.202507021305-0 | Fixed | RHSA-2025:10294 |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202506251005-0 | Fixed | RHSA-2025:9725 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202506252250-0 | Fixed | RHSA-2025:9750 |
| Red Hat Enterprise Linux 10 | glibc | Not affected | n/a |
| Red Hat Enterprise Linux 6 | compat-glibc | Not affected | n/a |
| Red Hat Enterprise Linux 6 | glibc | Not affected | n/a |
| Red Hat Enterprise Linux 7 | compat-glibc | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue can only be exploitable by a local attacker via a static setuid program that calls the dlopen function, causing the library to search LD_LIBRARY_PATH to locate the shared object name to load. No such programs have been found in Red Hat Enterprise Linux at the time of publishing this advisory. However, custom setuid programs, although strongly discouraged as a security practice, may exist and can not be discarded. Due to these reasons, this flaw has been rated with a moderate severity.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 20, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.59% (0.00590) | 46.35th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.39% (0.00392) | 30.78th | v5 (v2026.06.15) |
| May 17, 2025 | 0.04% (0.00044) | 13.10th | v4 (v2025.03.14) |
References (12)
- http://www.openwall.com/lists/oss-security/2025/05/16/7 Mailing List
- http://www.openwall.com/lists/oss-security/2025/05/17/2 ExploitMailing List
- https://access.redhat.com/security/cve/CVE-2025-4802 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2367468 Issue Tracking
- https://inbox.sourceware.org/libc-announce/3ac997b0-28a5-4129-af53-675efe4c2dec@redhat.com/T/#u
- https://lists.debian.org/debian-lts-announce/2025/05/msg00033.html
- https://nvd.nist.gov/vuln/detail/CVE-2025-4802
- https://sourceware.org/bugzilla/show_bug.cgi?id=32976 Issue Tracking
- https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380e Patch
- https://www.cve.org/CVERecord?id=CVE-2025-4802
- https://www.openwall.com/lists/oss-security/2025/05/16/7
- https://www.openwall.com/lists/oss-security/2025/05/17/2
Change history (0)
No recorded changes yet.