Today, CISA ordered U.S. federal agencies to secure their systems against an actively exploited vulnerability that lets attackers gain root privileges on many major Linux distributions. Dubbed 'Looney Tunables' by Qualys' Threat Research Unit (who discovered the bug) and tracked as CVE-2023-4911, this security vulnerability is due to a buffer overflow weakness in the GNU C Library's ld.so dynamic loader. The security flaw impacts systems running the latest releases of widely used Linux platforms, including Fedora, Ubuntu, and Debian in their default configurations. Administrators are urged to patch their systems as soon as possible, seeing that the vulnerability is now actively exploited and several proof-of-concept (PoC) exploits have been released online since its disclosure in early October. "With the capability to provide full root access on popular platforms like Fedora, Ubuntu, and Debian, it's imperative for system administrators to act swiftly," Qualys' Saeed Abbasi warned. CISA also added the actively exploited Linux flaw to its Known Exploited Vulnerabilities Catalog today, including it in its list of "frequent attack vectors for malicious cyber actors" and posing "significant risks to the federal enterprise." Following its inclusion in CISA's KEV list, U.S. Federal Civilian Executive Branch Agencies (FCEB) must patch Linux devices on their networks by December 12, as mandated by a binding operational directive (BOD 22-01) issued one year ago. Although the BOD 22-0...
CISA orders federal agencies to patch Looney Tunables Linux bug
BleepingComputer
·Sergiu Gatlan
·Published Nov 21, 2023
·Updated
Affected Software
1 affected component
GNU C Library
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses CISA's directive for federal agencies to patch a critical Linux vulnerability known as 'Looney Tunables.'
2
What security implications are discussed?
The vulnerability allows attackers to gain root privileges on various major Linux distributions, posing a significant security risk.
3
What software is primarily affected by the Looney Tunables vulnerability?
The Looney Tunables vulnerability primarily affects the GNU C Library used in many Linux systems.
4
Who identified the Looney Tunables vulnerability?
The vulnerability was identified by Qualys' Threat Research team.
5
What action did CISA order regarding the Looney Tunables vulnerability?
CISA ordered federal agencies to patch their systems to protect against the exploitation of this vulnerability.