AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2011-1658

LOW · CVSS 3.7 EPSS 0.31%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2011-04-08 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2011-1658
Severity
LOW
CVSS
3.7
EPSS
0.31%

Original NVD Description

ld.so in the GNU C Library (aka glibc or libc6) 2.13 and earlier expands the $ORIGIN dynamic string token when RPATH is composed entirely of this token, which might allow local users to gain privileges by creating a hard link in an arbitrary directory to a (1) setuid or (2) setgid program with this RPATH value, and then executing the program with a crafted value for the LD_PRELOAD environment variable, a different vulnerability than CVE-2010-3847 and CVE-2011-0536. NOTE: it is not expected that any standard operating-system distribution would ship an applicable setuid or setgid program.