Linux Kernel Improper Ownership Management Vulnerability
cve CVE-2023-0386 2 sources, 2 claims · Watch
CISA Known Exploited Vulnerabilities writes:
Linux Kernel Improper Ownership Management Vulnerability Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. This vulner… the claim
Linux Kernel Improper Ownership Management Vulnerability Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. This vulner… the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Cwes cwes | CISA Known Exploited Vulnerabilities | CWE-282receipt
What the source handed over{
"cveID": "CVE-2023-0386",
"cwes": "CWE-282",
"dateAdded": "2025-06-17",
"dueDate": "2025-07-08",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
"product": "Kernel",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
"vendorProject": "Linux",
"vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
} | — |
| Due date due_date | CISA Known Exploited Vulnerabilities | 2025-07-08receipt
What the source handed over{
"cveID": "CVE-2023-0386",
"cwes": "CWE-282",
"dateAdded": "2025-06-17",
"dueDate": "2025-07-08",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
"product": "Kernel",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
"vendorProject": "Linux",
"vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
} | — |
| Exploited exploited | CISA Known Exploited Vulnerabilities | yesreceipt
What the source handed over{
"cveID": "CVE-2023-0386",
"cwes": "CWE-282",
"dateAdded": "2025-06-17",
"dueDate": "2025-07-08",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
"product": "Kernel",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
"vendorProject": "Linux",
"vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
} | — |
| Forensic triage forensic_triage | CISA Known Exploited Vulnerabilities | falsereceipt
What the source handed over{
"cveID": "CVE-2023-0386",
"cwes": "CWE-282",
"dateAdded": "2025-06-17",
"dueDate": "2025-07-08",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
"product": "Kernel",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
"vendorProject": "Linux",
"vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
} | — |
| Known ransomware campaign use known_ransomware_campaign_use | CISA Known Exploited Vulnerabilities | Unknownreceipt
What the source handed over{
"cveID": "CVE-2023-0386",
"cwes": "CWE-282",
"dateAdded": "2025-06-17",
"dueDate": "2025-07-08",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
"product": "Kernel",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
"vendorProject": "Linux",
"vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
} | — |
| Platform platform | Metasploit exploit modules | Linuxreceipt
What the source handed over{
"actions": [],
"aliases": [],
"arch": "x64",
"author": [
"xkaneiki",
"sxlmnwb",
"Takahiro Yokoyama"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": true,
"default_credential": false,
"description": "This exploit targets the Linux kernel bug in OverlayFS.\n\n A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities\n was found in the Linux kernel's OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount.\n This uid mapping bug allows a local user to escalate their privileges on the system.",
"disclosure_date": "2023-03-22",
"fullname": "exploit/linux/local/cve_2023_0386_overlayfs_priv_esc",
"is_install_path": true,
"mod_time": "2026-05-25 09:47:44 +0000",
"name": "Local Privilege Escalation via CVE-2023-0386",
"needs_cleanup": true,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/linux/local/cve_2023_0386_overlayfs_priv_esc.rb",
"platform": "Linux",
"post_auth": false,
"rank": 600,
"ref_name": "linux/local/cve_2023_0386_overlayfs_priv_esc",
"references": [
"CVE-2023-0386",
"URL-https://github.com/sxlmnwb/CVE-2023-0386",
"URL-https://github.com/DataDog/security-labs-pocs/tree/main/proof-of-concept-exploits/overlayfs-cve-2023-0386",
"URL-https://securitylabs.datadoghq.com/articles/overlayfs-cve-2023-0386/",
"URL-https://www.vicarius.io/vsociety/posts/cve-2023-0386-a-linux-kernel-bug-in-overlayfs"
],
"rport": null,
"session_types": [
"shell",
"meterpreter"
],
"targets": [
"Automatic"
],
"type": "exploit"
} | — |
| Product product | CISA Known Exploited Vulnerabilities | Kernelreceipt
What the source handed over{
"cveID": "CVE-2023-0386",
"cwes": "CWE-282",
"dateAdded": "2025-06-17",
"dueDate": "2025-07-08",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
"product": "Kernel",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
"vendorProject": "Linux",
"vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
} | — |
| Rank rank | Metasploit exploit modules | 600 Excellent. Cannot crash the service. A memory-corruption exploit does not qualify. receipt
What the source handed over{
"actions": [],
"aliases": [],
"arch": "x64",
"author": [
"xkaneiki",
"sxlmnwb",
"Takahiro Yokoyama"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": true,
"default_credential": false,
"description": "This exploit targets the Linux kernel bug in OverlayFS.\n\n A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities\n was found in the Linux kernel's OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount.\n This uid mapping bug allows a local user to escalate their privileges on the system.",
"disclosure_date": "2023-03-22",
"fullname": "exploit/linux/local/cve_2023_0386_overlayfs_priv_esc",
"is_install_path": true,
"mod_time": "2026-05-25 09:47:44 +0000",
"name": "Local Privilege Escalation via CVE-2023-0386",
"needs_cleanup": true,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/linux/local/cve_2023_0386_overlayfs_priv_esc.rb",
"platform": "Linux",
"post_auth": false,
"rank": 600,
"ref_name": "linux/local/cve_2023_0386_overlayfs_priv_esc",
"references": [
"CVE-2023-0386",
"URL-https://github.com/sxlmnwb/CVE-2023-0386",
"URL-https://github.com/DataDog/security-labs-pocs/tree/main/proof-of-concept-exploits/overlayfs-cve-2023-0386",
"URL-https://securitylabs.datadoghq.com/articles/overlayfs-cve-2023-0386/",
"URL-https://www.vicarius.io/vsociety/posts/cve-2023-0386-a-linux-kernel-bug-in-overlayfs"
],
"rport": null,
"session_types": [
"shell",
"meterpreter"
],
"targets": [
"Automatic"
],
"type": "exploit"
} | — |
| Vendor project vendor_project | CISA Known Exploited Vulnerabilities | Linuxreceipt
What the source handed over{
"cveID": "CVE-2023-0386",
"cwes": "CWE-282",
"dateAdded": "2025-06-17",
"dueDate": "2025-07-08",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
"product": "Kernel",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
"vendorProject": "Linux",
"vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
} | — |
vulnerability
| Linux Kernel Improper Ownership Management Vulnerability zetlyn/cve-kev · 2025-06-17 | cwes CWE-282 due_date 2025-07-08 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Kernel vendor_project Linux |
exploit
| Local Privilege Escalation via CVE-2023-0386 zetlyn/cve-metasploit · 2023-03-22 | platform Linux rank 600 | source |