U.S. CISA adds Linux Kernel flaw to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-0386 | Local Privilege Escalation via OverlayFS in the Linux Kernel CVE-2023-0386 is an improper ownership management flaw (CWE-282) in the Linux kernel's OverlayFS subsystem: due to a user-namespace uid-mapping bug, a setuid file with file capabilities that is copied from a 'nosuid' mount into another mount can be executed as setuid without authorization. A local attacker with an ordinary low-privilege account can trigger the flaw simply by copying such a capable file, with no user interaction required. Successful exploitation yields local privilege escalation on the host, with high impact to confidentiality, integrity, and availability. Affected products include the Linux kernel, Ubuntu Linux, Debian Linux, and NetApp H-series appliance firmware (H300S, H410C, H410S, H500S, H700S); CISA's affected list names the Linux Kernel. The flaw is being actively exploited in the wild - CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-17, though ransomware use is listed as unknown. Do: Apply vendor-supplied fixed kernel updates from Canonical or Debian and reboot affected hosts so the patched kernel is loaded; NetApp H300S/H500S/H700S/H410S/H410C systems should install fixed firmware per NetApp's advisory. Because the flaw is in the CISA KEV catalog (added 2025-06-17), follow BOD 22-01 guidance: apply vendor mitigations or discontinue use where fixes are unavailable, prioritizing multi-user servers and any host with untrusted local accounts. | 7.8 | 8% | KEV |
| mass100M+ users (Ubuntu and Debian kernels ship OverlayFS system-wide; related reporting cites ~40% of Ubuntu users), plus an unknown number of NetApp H-series… |
Full article216 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel vulnerability to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Google Chromium V8 Out-of-Bounds Read and Write Vulnerability, tracked as CVE-2023-0386, to its Known Exploited Vulnerabilities (KEV) catalog.
The vulnerability, CVE-2023-0386 (CVSS score: 7.8), is an improper ownership vulnerability in the Linux kernel that can be exploited to escalate privileges on vulnerable systems.
“A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount.” reads the advisory “This uid mapping bug allows a local user to escalate their privileges on the system.”
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities by July 8, 2025.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/179104/hacking/u-s-cisa-adds-linux-kernel-flaw-to-its-known-exploited-vulnerabilities-catalog-2.html