CVE-2023-0386: Linux Kernel Improper Ownership Management Vulnerability

Published Jan 9, 2023
·
Updated

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

Other sources

An attacker with a low-privileged user on a Linux machine with an overlay mount which has a file capability in one of its layers may escalate his privileges up to root when copying a capable file from a nosuid mount into another mount. This vulnerability is similar to the CVE-2021-3847, but requires less permissions to run, so higher priority. The steps to reproduce:

1. Mount a FUSE filesystem that exposes a root owned setuid/setgid binary that is world writable. 2. unshare user/mount namespaces 3. mount an overlay with the FUSE fs as the lower dir, and a user writable upper dir (as usual). Make sure that the upper dir is on a filesystem that is not mounted with nosuid. 4. touch the file at the merged path to update its mtime, which will trigger a copy-up of the file 5. the setuid/gid bitsare not cleared by the kernel, so the upper directory will contain a copy of the binary with the setuid bits. 6. run the binary from the upper dir and it will run as root

The previous CVE-2021-3847 involves file capabilities (xattrs). Xattrs have special rules with user namespaces, so the copied up file will not have capabilities that are valid on the host. The "new" bug makes use of setgid/setuid bits, which are not user-namespace specific. CVE-2021-3847 also specifically talks about USB mounts, which requires physical access and is disabled in most production environments. FUSE on the other hand does not require physical access, and is installed in many production environments (Ubuntu out of the box, RH/Fedora if any number of popular packages are installed).

To recap: the existing reproducer (POC) for this one escalates privileges to root if FUSE is installed on the system, and if unprivileged overlayfs mounts are allowed (i.e., any kernel 5.11+ with unprivileged user namespaces enabled).

References: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a

Reference for the previous similar CVE-2021-3847: https://www.openwall.com/lists/oss-security/2021/10/14/3

Red Hat

Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

CISA

Affected Software

24 affected componentsFixes available
redhat/Linux kernel<6.2
6.2
Linux Linux kernel>=5.11<5.15.91
Linux Linux kernel>=5.16<6.1.9
Linux Linux kernel=6.2-rc1
Linux Linux kernel=6.2-rc2
Linux Linux kernel=6.2-rc3
Linux Linux kernel=6.2-rc4
Linux Linux kernel=6.2-rc5
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
Linux Kernel
Debian Debian Linux=10.0
All of the following
NetApp H300s Firmware
NetApp H300s
All of the following
NetApp H500s Firmware
NetApp H500s
All of the following
NetApp H700s Firmware
NetApp H700s
All of the following
NetApp H410s Firmware
NetApp H410s
All of the following
NetApp H410c Firmware
NetApp H410c
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
Canonical Ubuntu Linux=22.04

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
  2. Upgrade

    Upgrade redhat/Linux kernel to a version that resolves this vulnerability.

    Fixed in 6.2
  3. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.223-1
  4. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.234-1
  5. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 6.1.129-1
  6. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 6.1.135-1
  7. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 6.12.25-1
  8. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 6.12.27-1
  9. Configuration

    Make sure that the upper dir is on a filesystem that is not mounted with `nosuid`.

    overlayfs upper dir filesystem nosuid mount option = not set
  10. Compensating control

    Follow applicable BOD 22-01 guidance for cloud services.

  11. Compensating control

    Discontinue use of the product if mitigations are unavailable.

Event History

Jan 9, 2023
Data Sourced
via Red Hat·07:50 PM
DescriptionSeverityAffected Software
Mar 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:13 AM
Description
Dec 1, 2024
Data Sourced
via Ubuntu·03:59 AM
RemedyDescriptionSeverityAffected Software
Jun 17, 2025
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Jun 18, 2025
News Published
via BleepingComputer·01:54 PM
News Published
via BleepingComputer·01:56 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-0386?

CVE-2023-0386 has a high severity level due to its capability for local privilege escalation.

2

How do I fix CVE-2023-0386?

To address CVE-2023-0386, update to the patched Linux kernel versions 6.2 or any recommended versions from your Linux distribution.

3

Which Linux kernel versions are affected by CVE-2023-0386?

CVE-2023-0386 affects Linux kernel versions from 5.11 up to 6.1.9 and includes several release candidates of 6.2.

4

Can CVE-2023-0386 be exploited remotely?

CVE-2023-0386 is not remotely exploitable; it requires local access to the system.

5

What specific functionality is compromised by CVE-2023-0386?

CVE-2023-0386 compromises the security of setuid files with capabilities in the Linux kernel's OverlayFS subsystem.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203