CVE-2025-4802

NameCVE-2025-4802
DescriptionUntrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4181-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
glibc (PTS)bullseye2.31-13+deb11u11vulnerable
bullseye (security)2.31-13+deb11u13fixed
bookworm2.36-9+deb12u13fixed
bookworm (security)2.36-9+deb12u7vulnerable
forky, sid, trixie2.41-12fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
glibcsourcebullseye2.31-13+deb11u13DLA-4181-1
glibcsourcebookworm2.36-9+deb12u11
glibcsource(unstable)2.39-4

Notes

Introduced with: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=10e93d968716ab82931d593bada121c17c0a4b93 (glibc-2.27)
Fixed by: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=5451fa962cd0a90a0e2ec1d8910a559ace02bba0 (glibc-2.39)
https://sourceware.org/bugzilla/show_bug.cgi?id=32976
https://www.openwall.com/lists/oss-security/2025/05/17/2

Search for package or bug name: Reporting problems