A new Linux bug referred to as ' Looney Tunables' allows local attackers to gain administrator privileges by exploiting a buffer overflow vulnerability in the ld.so loader of the GNU C Library .
See also: Company announcement about Free Download Manager site that spread Linux malware

The GNU General C Library (glibc) is the C library of the GNU system and is present in most versions of the Linux kernel. It provides the necessary functionality, including system calls such as open, malloc, printf, exit , and others, that are necessary for normal program execution.
The dynamic loader within glibc is very important, as it is responsible for preparing and executing programs on systems that use glibc.
Looney Tunables, discovered by the Qualys Threat Research Team, was introduced in April 2021, with the release of glibc 2.34, through an action described as a fix for SXID_ERASE in setuid programs.
“Its successful exploitation, which led to full root privileges on major distributions such as Fedora, Ubuntu, and Debian, reveals the severity and widespread nature of this vulnerability,” said Saeed Abbasi, Product Manager in Qualys Threat Research.
“Although we currently hold our exploit code, the ease with which the buffer overflow can be turned into a data attack suggests that other groups of researchers may soon be able to createand publish exploits.“
See also: SprySOCKS: New Linux backdoor used in Chinese espionage campaigns

This could compromise countless systems, especially considering the widespread use of glibc in Linux distributions.
Looney Tunables is enabled when editing the GLIBC_TUNABLES environment variable in default installations of Debian 12 and 13, Ubuntu 22.04 and 23.04, and Fedora 37 and 38 (Alpine Linux, which uses the musl libc, is not affected). This issue could allow a local attacker to maliciously use configurable GLIBC_TUNABLES environment variables when launching executables with SUID permissions to execute code with elevated privileges.
Attackers with low privileges can exploit this high severity vulnerability in low-sophistication attacks that do not require user interaction.
In recent years, Qualys researchers have discovered other serious Linux security issues that allow attackers to gain root privileges in the default configurations of many Linux distributions. The list includes a vulnerability in Polkit 's pkexec agent, another at the kernel filesystem level , and the Unix sudo program .
See also: Free Download Manager site redirected Linux users to malware for years
To protect yourself from the bug, install the latest updates for the major Linux distributions. The effectiveness of the patch depends on how quickly users install the update and how often they update their systems. It is important to follow recommended security practices, such as regularly updating the operating system, to ensure the effectiveness of the patch. Linux distribution manufacturers are constantly working to provide updates and fixes for any security issues. However, the effectiveness of the updates depends on user awareness and response. It is important to update your system regularly and install available updates to protect yourself from such vulnerabilities.
