VDB

RHSA-2025:9028

RHSA-2025:9028 PUBLISHED CVSS 7 HIGH

A flaw was found in the glibc library. A statically linked setuid binary that calls dlopen(), including internal dlopen() calls after setlocale() or calls to NSS functions such as getaddrinfo(), may incorrectly search LD_LIBRARY_PATH to determine which library to load, allowing a local attacker to load malicious shared libraries, escalate privileges and execute arbitrary code.

Risk Scores

CVSS 3.1
7
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatregistry.redhat.io/discovery/discovery-server-rhel9@sha256:dcd0d1f2506998720ba82cbb4090151f4c7dfc209e9f938bd3a5898b28e5be34_amd64 as a component of Red Hat Discovery 1.14*, *
Red Hatregistry.redhat.io/discovery/discovery-server-rhel9@sha256:965b6d045793756053e646090f2b378d94d01c043f5e949d064d8c16f3062dd9_arm64 as a component of Red Hat Discovery 1.14*, *

Timeline

  • Jun 12, 2025 CVE Published
  • Aug 16, 2026 CVE Updated
  • Aug 16, 2026 Distribution Patch
  • Aug 16, 2026 Distribution Patch
  • Aug 16, 2026 Security Advisory
  • Aug 16, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›