Security Advisory

CVE-2023-0386

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-03-22 00:00:00
Last updated 2025-10-21 23:15:22
Assigner redhat
State PUBLISHED

Description

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.