CVE-2025-4802
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
- Affected products
- Almalinux, Astra Linux, Centos, Debian, Gnu C Library, Linuxmint, Red Hat, Red Os
- Gnu Glibc
- ≤ 2.38
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.6% (44th percentile)
- Weakness
- CWE-426
- NVD status
- Modified
- Published
- 2025-05-16
- Attack patterns
- CAPEC-13
CVE-2025-4802 at NVD
1 known exploit for CVE-2025-4802
Proof-of-concept code and exploit modules indexed by Sploitus