UBUNTU-CVE-2023-0386
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-0386
UBUNTU-CVE-2023-0386
Summary:
Details: A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.
References: https://ubuntu.com/security/CVE-2023-0386, https://git.kernel.org/linus/4f11ada10d0ad3fd53e2bd67806351de63a4f9c3, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a, https://ubuntu.com/security/notices/USN-6025-1, https://ubuntu.com/security/notices/USN-6040-1, https://ubuntu.com/security/notices/USN-6043-1, https://ubuntu.com/security/notices/USN-6057-1, https://ubuntu.com/security/notices/USN-6071-1, https://ubuntu.com/security/notices/USN-6072-1, https://ubuntu.com/security/notices/USN-6134-1, https://www.cve.org/CVERecord?id=CVE-2023-0386, https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/[email protected]~16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
