CVE-2025-4802General(gnu / glibc)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-426

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • glibc

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-13); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
glibc

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-13: 2Mentions · 2026-04-30: 1Mentions · 2026-07-29: 1PoC Mentioned / Linked · 2026-04-30: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-30: 1Technical Details · 2026-07-29: 104-1304-3007-29
Signal classification2 categories
General
250.0%
Disclosure
250.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-132
General2
2026-04-301
Disclosure1
2026-07-291
Disclosure1
Full discourse4 posts
  • 0xor0ne@0xor0ne
    Disclosure

    Analysis of CVE-2025-4802: glibc 2.27-2.38 fails to sanitize LD_LIBRARY_PATH before dlopen() in statically linked SUID binaries, allowing arbitrary library loading and LPE. https://allelesecurity.com/libc-vuln-analysis/ Infosec https://t.co/qHEM1iX8eH

    Post summary

    The text presents a detailed analysis of CVE-2025-4802, describing how glibc's lack of sanitization enables local privilege escalation, but does not provide a PoC, exploit code, active exploitation evidence, or patch information.

    0232154819.9K
    91.8K followersView on X
  • Allele Security Intelligence@alleleintel
    General

    We chose a vulnerability in glibc (CVE-2025-4802) to teach students registered in our binary exploitation training the importance of the libc, loader, dynamic linker, and the kernel in making the execution of a modern Linux binary possible. Furthermore, it demonstrates how a small oversight in the static glibc code allowed arbitrary libraries to be loaded into privileged code. Do you know the crucial role of the auxiliary vector? Or the main differences between dynamically and statically compiled binaries?

    Post summary

    The post references CVE-2025-4802 as a teaching example, explaining a static glibc oversight that permits arbitrary library loading into privileged code, with no PoC, exploit, patch or active exploitation mentioned.

    25048405.0K
    1.1K followersView on X
  • Allele Security Intelligence@alleleintel
    General

    Check out the blog post for a brief analysis of CVE-2025-4802. https://allelesecurity.com/libc-vuln-analysis/

    Post summary

    The message simply points to a blog post offering a brief analysis of CVE‑2025‑4802, with no further technical or actionable details provided in the text.

    011034222.1K
    1.1K followersView on X
  • Kimberly K. Maher@Peacemakerproje
    Disclosure

    C educators — May 2026 updates + a note on AI: • glibc CVE-2025-4802 (LD_LIBRARY_PATH in setuid binaries) • Linux ksmbd use-after-free (CVE-2025-37899), found with AI help • GCC 15 in Fedora 42 with C23 defaults • Clang/LLVM nearing full C23 support • @GitHub Copilot Coding Agent launched • @SQLite 3.50.0 (25th anniversary) AI is simply a tool. It is not here to replace you. You still know the students, notice when they’re stuck, and decide what help they need next. AI just makes everyday tasks easier so you have more time for real teaching. It can draft practice examples, suggest clearer explanations, clean up rough student code for comparison, or generate quick checks. Keep it plain and useful. Stay in charge — always check what it produces. Used this way, AI is a helpful assistant, not a replacement. You already do excellent work. Let’s explore AI carefully and keep the focus on the students. Thoughts? #CProgramming #CLang #C23 #AIinEducation #CodingEducation #EdTech

    Post summary

    The post lists a few CVEs and other software updates, providing minimal technical details but no exploit, patch, or mitigation information – essentially a brief disclosure.

    0101058
    2.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnuglibc---

Explore more