CVE-2010-3856: High severity gnu c library vulnerability

Published Oct 22, 2010
·
Updated

ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LDAUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.

Other sources

Tavis Ormandy pointed out that glibc does not properly sanitize DSOs that are loaded using LDAUDIT facility. Tavis quoted:

In order to be preloaded during the execution of a privileged program, a library must be setuid and in the trusted library search path. This is a reasonable design, in order to be loaded a system administrator must brand a library as safe before it will be loaded across privilege boundaries.

This allows developers who design their programs to operate safely while running as setuid are able to do so. The same conditions do not apply to LDAUDIT, which will load an arbitrary DSOs, regardless of whether it has been designed to operate safely or not.

Tavis found out that by exploiting unsafely designed DSO constructors in trusted directories it is possible to achieve privilege escalation.

Acknowledgements:

Red Hat would like to thank Ben Hawkes and Tavis Ormandy for reporting this issue.

Red Hat

Affected Software

55 affected components
GNU glibc<=2.11.2
GNU glibc=1.00
GNU glibc=1.01
GNU glibc=1.02
GNU glibc=1.03
GNU glibc=1.04
GNU glibc=1.05
GNU glibc=1.06
GNU glibc=1.07
GNU glibc=1.08
GNU glibc=1.09
GNU glibc=1.09.1
GNU glibc=2.0
GNU glibc=2.0.1
GNU glibc=2.0.2
GNU glibc=2.0.3
GNU glibc=2.0.4
GNU glibc=2.0.5
GNU glibc=2.0.6
GNU glibc=2.1
GNU glibc=2.1.1
GNU glibc=2.1.1.6
GNU glibc=2.1.2
GNU glibc=2.1.3
GNU glibc=2.1.3.10
GNU glibc=2.1.9
GNU glibc=2.2
GNU glibc=2.2.1
GNU glibc=2.2.2
GNU glibc=2.2.3
GNU glibc=2.2.4
GNU glibc=2.2.5
GNU glibc=2.3
GNU glibc=2.3.1
GNU glibc=2.3.2
GNU glibc=2.3.3
GNU glibc=2.3.4
GNU glibc=2.3.5
GNU glibc=2.3.6
GNU glibc=2.3.10
GNU glibc=2.4
GNU glibc=2.5
GNU glibc=2.5.1
GNU glibc=2.6
GNU glibc=2.6.1
GNU glibc=2.7
GNU glibc=2.8
GNU glibc=2.9
GNU glibc=2.10
GNU glibc=2.10.1
GNU glibc=2.10.2
GNU glibc=2.11
GNU glibc=2.11.1
GNU glibc=2.12.0
GNU glibc=2.12.1

Event History

Oct 22, 2010
Data Sourced
08:28 AM
DescriptionSeverityAffected Software
Jan 7, 2011
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2010-3856?

CVE-2010-3856 is considered a high severity vulnerability due to its potential for local privilege escalation.

2

How do I fix CVE-2010-3856?

To mitigate the risk from CVE-2010-3856, update the GNU C Library (glibc) to versions 2.11.3 or 2.12.2 and later.

3

Who is affected by CVE-2010-3856?

CVE-2010-3856 affects all versions of the GNU C Library (glibc) prior to 2.11.3 and certain versions of 2.12.x.

4

What can attackers do with CVE-2010-3856?

Attackers can exploit CVE-2010-3856 to execute arbitrary code with elevated privileges via the LD_AUDIT environment variable.

5

Is there a workaround for CVE-2010-3856?

A temporary workaround for CVE-2010-3856 is to restrict the use of the LD_AUDIT environment variable until the software can be updated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203