CVE-2025-4802
Description
RHSA-2025:8686: glibc security update (Moderate)
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH Red Hat statement This issue can only be exploitable by a local attacker via a static setuid program that calls the dlopen function, causing the library to search LD_LIBRARY_PATH to locate the shared object name to load. No such programs have been found in Red Hat Enterprise Linux at the time of publishing thisβ¦
Description
glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH
Red Hat statement
This issue can only be exploitable by a local attacker via a static setuid program that calls the dlopen function, causing the library to search LD_LIBRARY_PATH to locate the shared object name to load. No such programs have been found in Red Hat Enterprise Linux at the time of publishing this advisory. However, custom setuid programs, although strongly discouraged as a security practice, may exist and can not be discarded. Due to these reasons, this flaw has been rated with a moderate severity.
CVSS v3: 7.0 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 7.7 Advanced Update Support | glibc-0:2.17-292.el7_7.3 | RHSA-2025:10220 | 2025-07-02T00:00:00Z |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | glibc-0:2.17-326.el7_9.5 | RHSA-2025:10219 | 2025-07-02T00:00:00Z |
| Red Hat Enterprise Linux 8 | glibc-0:2.28-251.el8_10.22 | RHSA-2025:8686 | 2025-06-09T00:00:00Z |
| Red Hat Enterprise Linux 8 | glibc-0:2.28-251.el8_10.22 | RHSA-2025:8686 | 2025-06-09T00:00:00Z |
| Red Hat Enterprise Linux 9 | glibc-0:2.34-168.el9_6.19 | RHSA-2025:8655 | 2025-06-09T00:00:00Z |
| Red Hat Enterprise Linux 9 | glibc-0:2.34-168.el9_6.19 | RHSA-2025:8655 | 2025-06-09T00:00:00Z |
| Red Hat Enterprise Linux 9.4 Extended Update Support | glibc-0:2.34-100.el9_4.12 | RHSA-2025:9336 | 2025-06-23T00:00:00Z |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202506251808-0 | RHSA-2025:9765 | 2025-07-02T00:00:00Z |
| Red Hat OpenShift Container Platform 4.17 | rhcos-417.94.202507021305-0 | RHSA-2025:10294 | 2025-07-09T00:00:00Z |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202506251005-0 | RHSA-2025:9725 | 2025-07-02T00:00:00Z |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202506252250-0 | RHSA-2025:9750 | 2025-07-01T00:00:00Z |
| Red Hat Discovery 1.14 | discovery/discovery-server-rhel9:1.14.5-1749654812 | RHSA-2025:9028 | 2025-06-12T00:00:00Z |
| Red Hat Discovery 2 | discovery/discovery-server-rhel9:2.0.0-1752592913 | RHSA-2025:11487 | 2025-07-21T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 10 | glibc | Not affected |
| Red Hat Enterprise Linux 6 | compat-glibc | Not affected |
| Red Hat Enterprise Linux 6 | glibc | Not affected |
| Red Hat Enterprise Linux 7 | compat-glibc | Not affected |
Apply commands
yum update -y glibc
# or:
dnf upgrade -y glibc
Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | Red Hat Enterprise Linux 10 | Not affected |
| redhat | Red Hat Enterprise Linux 6 | Not affected |
| redhat | Red Hat Enterprise Linux 6 | Not affected |
| redhat | Red Hat Enterprise Linux 7 | Not affected |
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 9 | fixed | |
| rocky | 8 | fixed | |
| debian | bookworm | fixed | 2.36-9+deb12u11 |
| debian | bullseye | fixed | 2.31-13+deb11u13 |
| debian | forky | fixed | 2.39-4 |
| debian | sid | fixed | 2.39-4 |
| debian | trixie | fixed | 2.39-4 |
| sles | affected | | |
| rocky | 9 | fixed | |
| almalinux | 9 | fixed | glibc-devel-2.34-168.el9_6.19.aarch64.rpm |
| almalinux | 8 | fixed | glibc-headers-2.28-251.el8_10.22.i686.rpm |
| rhel | 8 | fixed | |
References
- https://access.redhat.com/errata/RHSA-2025:8655
- https://errata.rockylinux.org/RLSA-2025:8686
- https://security-tracker.debian.org/tracker/CVE-2025-4802
- https://www.suse.com/security/cve/CVE-2025-4802.html
- https://errata.rockylinux.org/RLSA-2025:8655
- https://access.redhat.com/errata/RHSA-2025:8686
- https://bugzilla.redhat.com/2367468
- https://errata.almalinux.org/8/ALSA-2025-8686.html
- https://errata.almalinux.org/9/ALSA-2025-8655.html
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.