CVE-2010-3856 is a local privilege-escalation vulnerability in ld.so, the dynamic loader in the GNU C Library (glibc, also distributed as libc6). In affected versions prior to glibc 2.11.3 and in 2.12.x prior to 2.12.2, ld.so does not properly restrict the use of the LD_AUDIT environment variable when resolving dynamic shared objects as audit modules. This weakness allows a local user to cause the loader to reference an unsafe shared object from a trusted library directory. The issue was demonstrated with libpcprofile.so. By abusing the loader’s handling of audit objects, an attacker can influence privileged program execution and obtain elevated privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit module (Ruby file) that exploits a local privilege escalation vulnerability in the GNU C Library (glibc) dynamic linker (CVE-2010-3847 and CVE-2010-3856). The exploit abuses improper handling of the LD_AUDIT environment variable in setuid binaries, allowing an attacker to load arbitrary shared objects as root. The module checks for a vulnerable glibc version, the presence of a setuid executable (default: /bin/ping), and the existence of the libpcprofile.so library in a trusted path (commonly /lib). It uploads a malicious shared object and payload, manipulates file permissions, and executes the payload as root, providing full privilege escalation. The exploit is operational and tested on several Linux distributions. The code is structured as a standard Metasploit local exploit module, with options for specifying the SUID executable and writable directory. The main attack vector is local, requiring code execution on the target system. Key fingerprintable endpoints include the default SUID executable (/bin/ping), the writable directory (/tmp), the trusted library path (/lib), and the required libpcprofile.so shared object.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.