CVE-2023-0386

Advisory lineage Upstream: 0 Downstream: 40
Analyzed
Published: 22 Mar 2023, 00:00
Last modified:21 Oct 2025, 23:15

Vulnerability Summary

Overall Risk (default)
high
51/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
50.62% CRITICAL
51% probability -6.32%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

22 Mar 2023, 00:00
Published
Vulnerability first disclosed
17 Jun 2025, 00:00
Added to CISA KEV
Linux Kernel Improper Ownership Management Vulnerability
08 Jul 2025, 00:00
CISA Remediation Due
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
21 Oct 2025, 23:15
Last Modified
Vulnerability information updated

Description

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 50.62% Percentile: 98%

Techniques & Countermeasures

  • CWE-282Improper Ownership Management

    The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.

Affected Systems

  • canonicalubuntu_linux

    18.04 | 20.04 | 22.04

  • debiandebian_linux

    10.0

  • linuxlinux_kernel

    ≥ 5.11, < 5.15.91 | ≥ 5.16, < 6.1.9 | 6.2:rc1 | 6.2:rc2 | 6.2:rc3 | 6.2:rc4 | 6.2:rc5

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500s_firmware

    na

  • netapph700s_firmware

    na

References (7)