CVE-2025-4802
Publication date 16 May 2025
Last updated 30 May 2025
Ubuntu priority
Cvss 3 Severity Score
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
Status
Package | Ubuntu Release | Status |
---|---|---|
eglibc | 25.04 plucky | Not in release |
24.10 oracular | Not in release | |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
14.04 LTS trusty |
Not affected
|
|
glibc | 25.04 plucky |
Not affected
|
24.10 oracular |
Not affected
|
|
24.04 LTS noble |
Not affected
|
|
22.04 LTS jammy |
Fixed 2.35-0ubuntu3.10
|
|
20.04 LTS focal |
Fixed 2.31-0ubuntu9.18
|
|
18.04 LTS bionic |
Fixed 2.27-3ubuntu1.6+esm5
|
|
16.04 LTS xenial |
Not affected
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProSeverity score breakdown
Parameter | Value |
---|---|
Base score |
|
Attack vector | Local |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-7541-1
- GNU C Library vulnerability
- 28 May 2025
Other references
- https://www.cve.org/CVERecord?id=CVE-2025-4802
- https://sourceware.org/bugzilla/show_bug.cgi?id=32976
- https://www.openwall.com/lists/oss-security/2025/05/17/2
- http://www.openwall.com/lists/oss-security/2025/05/16/7
- https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380e
- https://sourceware.org/cgit/glibc/commit/?id=5451fa962cd0a90a0e2ec1d8910a559ace02bba0