What happened
GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges.
Affected versions
GNU C Library: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 52479glibc 2.38 - Buffer OverflowBeatriz Fresno Naumova2026-02-11VerifiedPoC-in-GitHub · Green-Avocado/CVE-2023-4911https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt★ 15Green-Avocado2023-10-04CandidatePoC-in-GitHub · leesh3288/CVE-2023-4911PoC for CVE-2023-4911★ 394leesh32882023-10-04CandidatePoC-in-GitHub · RickdeJager/CVE-2023-4911CVE-2023-4911 proof of concept★ 167RickdeJager2023-10-04CandidatePoC-in-GitHub · xiaoQ1z/CVE-2023-4911★ 1xiaoQ1z2023-10-08CandidatePoC-in-GitHub · silent6trinity/looney-tuneablesCVE-2023-4911★ 0silent6trinity2023-10-10CandidatePoC-in-GitHub · hadrian3689/looney-tunables-CVE-2023-4911★ 29hadrian36892023-10-10CandidatePoC-in-GitHub · ruycr4ft/CVE-2023-4911CVE-2023-4911★ 19ruycr4ft2023-10-11CandidatePoC-in-GitHub · guffre/CVE-2023-4911PoC for CVE-2023-4911 LooneyTuneables★ 0guffre2023-10-14CandidatePoC-in-GitHub · chaudharyarjun/LooneyPwnerExploit tool for CVE-2023-4911, targeting the 'Looney Tunables' glibc vulnerability in various Linux distributions.★ 43chaudharyarjun2023-10-17CandidatePoC-in-GitHub · KernelKrise/CVE-2023-4911Looney Tunables Local privilege escalation (CVE-2023-4911) workshop★ 18KernelKrise2023-10-25CandidatePoC-in-GitHub · Diego-AltF4/CVE-2023-4911Proof of concept for CVE-2023-4911 (Looney Tunables) discovered by Qualys Threat Research Unit★ 8Diego-AltF42023-10-28CandidatePoC-in-GitHub · teraGL/looneyCVELooney Tunables CVE-2023-4911★ 1teraGL2023-11-08CandidatePoC-in-GitHub · snurkeburk/Looney-TunablesPoC of CVE-2023-4911★ 0snurkeburk2023-12-10CandidatePoC-in-GitHub · puckiestyle/CVE-2023-4911★ 2puckiestyle2023-12-23CandidatePoC-in-GitHub · NishanthAnand21/CVE-2023-4911-PoCRepository containing a Proof of Concept (PoC) demonstrating the impact of CVE-2023-4911, a vulnerability in glibc's ld.so dynamic loader, exposing risks related to Looney Tunables.★ 7NishanthAnand212024-01-20CandidatePoC-in-GitHub · Billar42/CVE-2023-4911CVE-2023-4911-Looney-Tunables★ 0Billar422025-02-18CandidatePoC-in-GitHub · KillReal01/CVE-2023-4911★ 0KillReal012025-03-17CandidatePoC-in-GitHub · Aryan20057/CVE-2023-4911★ 0Aryan200572026-03-02CandidatePoC-in-GitHub · 0xMOGA/CVE-2023-4911-Lab★ 00xMOGA2026-04-11CandidatePoC-in-GitHub · jarpex/cve-2023-4911-exploit-optimizedPure C exploit for CVE-2023-4911 (Looney Tunables) — x86_64 & aarch64 implementations. Multi-processing brute-forcing, dynamic calibration, integrated ELF parser.★ 3jarpex2026-06-29CandidatePoC-in-GitHub · baeseungwon1010/CVE-2023-4911CVE-2023-4911 (Looney Tunables) analysis report and Docker reproduction lab★ 0baeseungwon10102026-07-12CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.