← back
CVE-2023-32629highobserved exploitationCWE-863

CVE-2023-32629

83Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 7.8epss 10%
from disclosure to weapon53 days
Published on NVDJul 26
1st PoC+53d
metasploitJul 26
VulnCheck+770d
exploitation probability
10%top 5% of all CVEs
observed exploitation
yesVulnCheck
9 public exploit(s)
In short

A flaw in Ubuntu's kernel allows a local user to gain higher system privileges by bypassing permission checks in the overlayfs feature. An attacker already logged into the system can exploit this to execute commands with administrator rights.

Technical detail

Local privilege escalation in overlayfs ovl_copy_up_meta_inode_data function that skips permission validation during ovl_do_setxattr calls. Attack vector requires local access; pre-condition is ability to interact with overlayfs mounts. Impact allows unprivileged users to escalate to root.

Summary generated and translated by AI from the official description.
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernels
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.