ZeroHour

CVE-2023-0386

KEVmass

Local Privilege Escalation via OverlayFS in the Linux Kernel

CISA: Linux Kernel Improper Ownership Management Vulnerability

CVSS 3.1
7.8 high
EPSS
8%p94
Published
()
KEV added
AI analysis

CVE-2023-0386 is an improper ownership management flaw (CWE-282) in the Linux kernel's OverlayFS subsystem: due to a user-namespace uid-mapping bug, a setuid file with file capabilities that is copied from a 'nosuid' mount into another mount can be executed as setuid without authorization. A local attacker with an ordinary low-privilege account can trigger the flaw simply by copying such a capable file, with no user interaction required. Successful exploitation yields local privilege escalation on the host, with high impact to confidentiality, integrity, and availability. Affected products include the Linux kernel, Ubuntu Linux, Debian Linux, and NetApp H-series appliance firmware (H300S, H410C, H410S, H500S, H700S); CISA's affected list names the Linux Kernel. The flaw is being actively exploited in the wild - CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-17, though ransomware use is listed as unknown.

What to do: Apply vendor-supplied fixed kernel updates from Canonical or Debian and reboot affected hosts so the patched kernel is loaded; NetApp H300S/H500S/H700S/H410S/H410C systems should install fixed firmware per NetApp's advisory. Because the flaw is in the CISA KEV catalog (added 2025-06-17), follow BOD 22-01 guidance: apply vendor mitigations or discontinue use where fixes are unavailable, prioritizing multi-user servers and any host with untrusted local accounts.

Affected
Linux kernel (OverlayFS subsystem)
Canonical Ubuntu Linux
Debian Linux
NetApp H300S firmware
NetApp H500S firmware
NetApp H700S firmware
NetApp H410S firmware
NetApp H410C firmware
Estimated exposure
mass100M+ users (Ubuntu and Debian kernels ship OverlayFS system-wide; related reporting cites ~40% of Ubuntu users), plus an unknown number of NetApp H-series… — Ubuntu and Debian distribute the Linux kernel with OverlayFS available by default and public reporting of related OverlayFS flaws estimates 40% of Ubuntu users affected, implying on the order of 100M+ users, with an additional but…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

CISA Known Exploited Vulnerability
Affected
Linux Kernel
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
debiannetappcanonicallinux
Products
debian linux, h300s firmware, h500s firmware, h700s firmware, h410s firmware, h410c firmware, ubuntu linux, linux kernel
Weakness
CWE-282
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news