← Back to browse · API

CVE-2023-0386

Severity
HIGH
CVSS
7.8
EPSS
0.0788
Risk score
58.96
CISA KEV
Yes
PoC
Yes
Published
2025-06-17
Modified
2025-06-17
First seen
2026-08-07
Aliases
EUVD-2023-12447, GHSA-P72Q-V88C-RPRQ
Products
Linux:Kernel, Linux:Kernel Linux kernel 6.2-rc6, unix
Sources
euvd EUVD-2023-12447
packetstorm bd2236092be59388bfdefee2|CVE-2023-0386
cisa.gov CVE-2023-0386
github 38ebf7f055b0af52d7dddd43|CVE-2023-0386

Description

Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

References