Sploitus

CVE-2025-4802

1 known exploit for CVE-2025-4802

Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).

Gnu Glibc
≤ 2.38
Fix
Available
CVSS 3.1
7.8 HIGH
EPSS
0.6% (44th percentile)
Weakness
CWE-426
NVD status
Modified
Published
2025-05-16
Attack patterns
CAPEC-13
CVE-2025-4802 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2025-4802

Proof-of-concept code and exploit modules indexed by Sploitus