Linux Kernel Improper Ownership Management Vulnerability

cve CVE-2023-0386 2 sources, 2 claims · Watch

CISA Known Exploited Vulnerabilities writes:
Linux Kernel Improper Ownership Management Vulnerability Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. This vulner… the claim

What each source says

PropertySourceSaidMeans here
Cwes
cwes
CISA Known Exploited VulnerabilitiesCWE-282
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-282
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 20:00 UTC
What the source handed over
{
  "cveID": "CVE-2023-0386",
  "cwes": "CWE-282",
  "dateAdded": "2025-06-17",
  "dueDate": "2025-07-08",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
  "product": "Kernel",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2025-07-08
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2025-07-08
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 20:00 UTC
What the source handed over
{
  "cveID": "CVE-2023-0386",
  "cwes": "CWE-282",
  "dateAdded": "2025-06-17",
  "dueDate": "2025-07-08",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
  "product": "Kernel",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 20:00 UTC
What the source handed over
{
  "cveID": "CVE-2023-0386",
  "cwes": "CWE-282",
  "dateAdded": "2025-06-17",
  "dueDate": "2025-07-08",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
  "product": "Kernel",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiesfalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 20:00 UTC
What the source handed over
{
  "cveID": "CVE-2023-0386",
  "cwes": "CWE-282",
  "dateAdded": "2025-06-17",
  "dueDate": "2025-07-08",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
  "product": "Kernel",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesUnknown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Unknown
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 20:00 UTC
What the source handed over
{
  "cveID": "CVE-2023-0386",
  "cwes": "CWE-282",
  "dateAdded": "2025-06-17",
  "dueDate": "2025-07-08",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
  "product": "Kernel",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
}
—
Platform
platform
Metasploit exploit modulesLinux
receipt
Source
Metasploit exploit modules
Its words
Linux
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:59 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "x64",
  "author": [
    "xkaneiki",
    "sxlmnwb",
    "Takahiro Yokoyama"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "This exploit targets the Linux kernel bug in OverlayFS.\n\n          A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities\n          was found in the Linux kernel's OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount.\n          This uid mapping bug allows a local user to escalate their privileges on the system.",
  "disclosure_date": "2023-03-22",
  "fullname": "exploit/linux/local/cve_2023_0386_overlayfs_priv_esc",
  "is_install_path": true,
  "mod_time": "2026-05-25 09:47:44 +0000",
  "name": "Local Privilege Escalation via CVE-2023-0386",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/linux/local/cve_2023_0386_overlayfs_priv_esc.rb",
  "platform": "Linux",
  "post_auth": false,
  "rank": 600,
  "ref_name": "linux/local/cve_2023_0386_overlayfs_priv_esc",
  "references": [
    "CVE-2023-0386",
    "URL-https://github.com/sxlmnwb/CVE-2023-0386",
    "URL-https://github.com/DataDog/security-labs-pocs/tree/main/proof-of-concept-exploits/overlayfs-cve-2023-0386",
    "URL-https://securitylabs.datadoghq.com/articles/overlayfs-cve-2023-0386/",
    "URL-https://www.vicarius.io/vsociety/posts/cve-2023-0386-a-linux-kernel-bug-in-overlayfs"
  ],
  "rport": null,
  "session_types": [
    "shell",
    "meterpreter"
  ],
  "targets": [
    "Automatic"
  ],
  "type": "exploit"
}
—
Product
product
CISA Known Exploited VulnerabilitiesKernel
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Kernel
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 20:00 UTC
What the source handed over
{
  "cveID": "CVE-2023-0386",
  "cwes": "CWE-282",
  "dateAdded": "2025-06-17",
  "dueDate": "2025-07-08",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
  "product": "Kernel",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
}
—
Rank
rank
Metasploit exploit modules600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:59 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "x64",
  "author": [
    "xkaneiki",
    "sxlmnwb",
    "Takahiro Yokoyama"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "This exploit targets the Linux kernel bug in OverlayFS.\n\n          A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities\n          was found in the Linux kernel's OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount.\n          This uid mapping bug allows a local user to escalate their privileges on the system.",
  "disclosure_date": "2023-03-22",
  "fullname": "exploit/linux/local/cve_2023_0386_overlayfs_priv_esc",
  "is_install_path": true,
  "mod_time": "2026-05-25 09:47:44 +0000",
  "name": "Local Privilege Escalation via CVE-2023-0386",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/linux/local/cve_2023_0386_overlayfs_priv_esc.rb",
  "platform": "Linux",
  "post_auth": false,
  "rank": 600,
  "ref_name": "linux/local/cve_2023_0386_overlayfs_priv_esc",
  "references": [
    "CVE-2023-0386",
    "URL-https://github.com/sxlmnwb/CVE-2023-0386",
    "URL-https://github.com/DataDog/security-labs-pocs/tree/main/proof-of-concept-exploits/overlayfs-cve-2023-0386",
    "URL-https://securitylabs.datadoghq.com/articles/overlayfs-cve-2023-0386/",
    "URL-https://www.vicarius.io/vsociety/posts/cve-2023-0386-a-linux-kernel-bug-in-overlayfs"
  ],
  "rport": null,
  "session_types": [
    "shell",
    "meterpreter"
  ],
  "targets": [
    "Automatic"
  ],
  "type": "exploit"
}
—
Vendor project
vendor_project
CISA Known Exploited VulnerabilitiesLinux
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Linux
Read by
field:vendorProject
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 20:00 UTC
What the source handed over
{
  "cveID": "CVE-2023-0386",
  "cwes": "CWE-282",
  "dateAdded": "2025-06-17",
  "dueDate": "2025-07-08",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
  "product": "Kernel",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
}
—

vulnerability

Linux Kernel Improper Ownership Management Vulnerability
zetlyn/cve-kev · 2025-06-17
cwes CWE-282 due_date 2025-07-08 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Kernel vendor_project Linux

exploit

Local Privilege Escalation via CVE-2023-0386
zetlyn/cve-metasploit · 2023-03-22
platform Linux rank 600 source