The GNU C Library project disclosed CVE-2025-4802, a local privilege-escalation flaw affecting glibc versions 2.27 through 2.38. The bug causes statically linked setuid/setgid ELF binaries that call dlopen()—directly or indirectly through functions such as setlocale, getaddrinfo, or other NSS-related paths—to incorrectly honor LD_LIBRARY_PATH in secure execution mode, allowing attacker-controlled libraries to be loaded and executed with elevated privileges. Upstream tracked the issue in advisory GLIBC-SA-2025-0002, describing it as locally exploitable and dependent on the presence of a privileged static binary that invokes dynamic loading.
Technical analysis traced the flaw to a 2017 glibc change that removed trusted-path enforcement during runtime path initialization, while the fix moved secure-mode environment sanitization earlier in _dl_non_dynamic_init() so variables such as LD_LIBRARY_PATH are cleared before library search paths are built; the correction landed upstream in glibc 2.39. Public writeups and mailing-list discussion included proof-of-concept exploitation using malicious NSS modules to achieve code execution as root or with SGID privileges, but both the advisory and follow-on analysis said practical exposure appears limited because no default-distribution binaries meeting the exploit conditions had been identified, though custom privileged programs remain at risk.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
In response to the advisory, Solar Designer posted a proof of concept showing a statically linked SGID test program loading a malicious NSS library from the current directory via LD_LIBRARY_PATH. He also reported that one hardened Rocky Linux 9.5 downstream glibc build blocked the SGID test despite lacking the exact upstream backport.
The GNU C Library project published security advisory GLIBC-SA-2025-0002 for CVE-2025-4802, warning that statically linked setuid binaries calling dlopen may incorrectly search LD_LIBRARY_PATH and execute attacker-controlled library code. The advisory said exploitation was only considered locally viable and that no vulnerable program had been identified at publication time.
glibc fixed the issue by moving secure-mode environment sanitization earlier in _dl_non_dynamic_init() so LD_LIBRARY_PATH and related variables are cleared before path initialization. The fix was implemented in commit 5451fa962cd0a90a0e2ec1d8910a559ace02bba0.
A glibc commit removed trusted-path enforcement from fillin_rpath(), allowing LD_LIBRARY_PATH to be processed in secure execution contexts for affected static privileged binaries. Later analyses identified this 2017 change as the root cause of CVE-2025-4802.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
allelesecurity.com
Open sourceallelesecurity.com
Open sourcesourceware.org
Open sourceopenwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.