Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-142193

glibc: Remove default value for LD_PROFILE_OUTPUT [rhel-10]

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • rhel-10.2.z
    • rhel-8.10.z, rhel-9.7.z, rhel-10.1.z, rhel-9.8, rhel-10.2
    • glibc
    • glibc-2.39-114.el10
    • None
    • Low
    • ZStream
    • Hide
      7b543dcdf97d07fd4346feb17916e08fe83ad0ae
      34d98aea6c1eaf7750a992bae55b2bca24898eab
      e8502182f09211663c1583960442eb6ff502a33e
      458a6a2b935f60a25a136846fe8b7a4723296dda
      229f65f5f322609283c7104c80c8af6434dff628
      364426a59ee30ee3e528e5b5cae36b5dee045320
      1e1ad714ee9a663eda0e2bffad1d9f258b00a4e9
      Show
      7b543dcdf97d07fd4346feb17916e08fe83ad0ae 34d98aea6c1eaf7750a992bae55b2bca24898eab e8502182f09211663c1583960442eb6ff502a33e 458a6a2b935f60a25a136846fe8b7a4723296dda 229f65f5f322609283c7104c80c8af6434dff628 364426a59ee30ee3e528e5b5cae36b5dee045320 1e1ad714ee9a663eda0e2bffad1d9f258b00a4e9
    • 1
    • rhel-pt-c-libs
    • 3
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • PT C Libraries 2026 S03
    • Regression Exception
    • Requested
    • None
    • Unspecified Release Note Type - Unknown
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      Use of LD_PROFILE without setting LD_PROFILE_OUTPUT is currently insecure due to the default /var/tmp. We should backport this upstream commit to remove the default.

      commit 7b543dcdf97d07fd4346feb17916e08fe83ad0ae
      Author: Florian Weimer <fweimer@redhat.com>
      Date:   Thu Jan 15 22:29:46 2026 +0100
      
          elf: Ignore LD_PROFILE if LD_PROFILE_OUTPUT is not set (bug 33797)
          
          The previous default for LD_PROFILE_OUTPUT, /var/tmp, is insecure
          because it's typically a 1777 directory, and other systems could
          place malicious files there which interfere with execution.
          
          Requiring the user to specify a profiling directory mitigates
          the impact of bug 33797.  Clear LD_PROFILE_OUTPUT alongside
          with LD_PROFILE.
          
          Rework the test not to use predictable file names.
          
          Reviewed-by: Carlos O'Donell <carlos@redhat.com>
      

       

      Upstream does not treat this as a security vulnerability.

              xmcoufal Martin Coufal
              fweimer@redhat.com Florian Weimer
              Patsy Griffin Patsy Griffin
              Martin Coufal Martin Coufal
              Votes:
              0 Vote for this issue
              Watchers:
              10 Start watching this issue

                Created:
                Updated: