Beveiligingsadvies

CVE-2023-0386

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-03-22 00:00:00
Laatst bijgewerkt 2025-10-21 23:15:22
Toegewezen door redhat
CVSS-score 7.8
Status PUBLISHED

Beschrijving

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.