CVE-2023-0386
KEVmassLocal Privilege Escalation via OverlayFS in the Linux Kernel
CISA: Linux Kernel Improper Ownership Management Vulnerability
CVE-2023-0386 is an improper ownership management flaw (CWE-282) in the Linux kernel's OverlayFS subsystem: due to a user-namespace uid-mapping bug, a setuid file with file capabilities that is copied from a 'nosuid' mount into another mount can be executed as setuid without authorization. A local attacker with an ordinary low-privilege account can trigger the flaw simply by copying such a capable file, with no user interaction required. Successful exploitation yields local privilege escalation on the host, with high impact to confidentiality, integrity, and availability. Affected products include the Linux kernel, Ubuntu Linux, Debian Linux, and NetApp H-series appliance firmware (H300S, H410C, H410S, H500S, H700S); CISA's affected list names the Linux Kernel. The flaw is being actively exploited in the wild - CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-17, though ransomware use is listed as unknown.
What to do: Apply vendor-supplied fixed kernel updates from Canonical or Debian and reboot affected hosts so the patched kernel is loaded; NetApp H300S/H500S/H700S/H410S/H410C systems should install fixed firmware per NetApp's advisory. Because the flaw is in the CISA KEV catalog (added 2025-06-17), follow BOD 22-01 guidance: apply vendor mitigations or discontinue use where fixes are unavailable, prioritizing multi-user servers and any host with untrusted local accounts.
| Linux kernel (OverlayFS subsystem) | — |
| Canonical Ubuntu Linux | — |
| Debian Linux | — |
| NetApp H300S firmware | — |
| NetApp H500S firmware | — |
| NetApp H700S firmware | — |
| NetApp H410S firmware | — |
| NetApp H410C firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.
- Affected
- Linux Kernel
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown