PT-2023-1959 · Linux+10 · Linux Kernel+10
CVE-2023-0386
·
Published
2023-01-24
·
Updated
2026-09-02
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux Kernel versions prior to 6.2
Description
A flaw exists in the OverlayFS subsystem of the Linux kernel regarding improper ownership management and access control when processing setuid and setgid attributes. The issue occurs when a user copies a capable file from a nosuid mount into another mount, resulting in a uid mapping bug. This allows a local user to create a file with the SUID flag in directories such as
/tmp to escalate privileges to root. The issue is particularly relevant on systems where the FUSE subsystem is installed and unprivileged users are allowed to mount OverlayFS partitions (starting from Linux kernel 5.11 with unprivileged user namespaces enabled). This flaw has been reported as actively exploited in real-world attacks, specifically targeting public-facing servers, cloud platforms, and CI/CD systems.Recommendations
Update the Linux kernel to version 6.2 or later.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu