Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is exploitable for code execution
Conclusion & alert: CVE-2007-3508 is rated Moderate Risk (41.7/100): CVSS High severity, with low exploitation likelihood (EPSS 0.45%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.05% | 0.45% | +0.40% |
| 2 | 2026-02-20 | 0.05% | 0.05% | +0.00% |
| 3 | 2025-03-30 | — | 0.05% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.2 | 2.0 | HIGH |
|
3.9 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2007-3508: no source package rows; 0 state rows across 0 repos (none); fixed 0, open 0. | https://security.alpinelinux.org/vuln/CVE-2007-3508 |
debian
|
unimportant | CVE-2007-3508 unimportant priority: Debian including 1 source packages (glibc), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2007-3508 |
gentoo
|
normal | CVE-2007-3508: 1 GLSA(s) (200707-04), 1 atom(s) (sys-libs/glibc); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2007-3508 |
redhat
|
— | — | https://access.redhat.com/security/cve/CVE-2007-3508 |
ubuntu
|
negligible | CVE-2007-3508 negligible priority: Ubuntu including 1 source packages (glibc), 8 status rows across 8 suites (dapper, edgy, feisty, gutsy, hardy, intrepid, jaunty, upstream): ignored 3, not-affected 3, released 2. | https://ubuntu.com/security/CVE-2007-3508 |
Based on the analysis of Red Hat and several Glibc developers, Mandriva does not believe this to be exploitable.
After careful analysis by Red Hat and several Glibc developers, it has been determined that this bug is not exploitable. For more information please see Red Hat Bugzilla bug #247208 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=247208