New Linux glibc flaw lets attackers get root on major distros
ID: 697f81fc-3a40-5716-b4ad-e35a921ad2d1
STIX ID: report--697f81fc-3a40-5716-b4ad-e35a921ad2d1
Feed Name: Bleeping Computer
Qualys researchers disclosed a critical glibc vulnerability (CVE-2023-6246) — a heap-based buffer overflow in __vsyslog_internal used by syslog/vsyslog — that can allow unprivileged local users to gain full root privileges on default installations of several major Linux distributions (confirmed on Debian 12/13, Ubuntu 23.04/23.10, Fedora 37–39). Exploitation requires specific conditions (such as an unusually long argv[0] or openlog() ident), and the researchers also identified additional related glibc flaws; the report emphasizes broad impact due to glibc's ubiquity and notes past glibc/kernel/sudo flaws have been exploited in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
