CVE-2023-0386

Updated: 2025-11-10 03:10:07.582483

Description:

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Known exploits

Added Date Description Due Date Notes
2025-06-17 Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system. 2025-07-08 This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Already Fixed 2024-01-20 08:37:44
CentOS 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2025-09-20 18:19:13
CentOS 7 ELS kernel 3.10.0 7.8 HIGH Released CLSA-2025:1759431860 2025-10-15 20:22:53
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2023:1686585068 2023-06-13 09:06:02
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2023:1686651204 2023-06-13 09:06:02
CloudLinux 6 ELS kernel 2.6.32 7.8 HIGH Ignored 2025-09-23 12:36:24 Postponed until request or high risk detected
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2025-11-02 12:47:55
Oracle Linux 7 ELS kernel 3.10.0 7.8 HIGH Released CLSA-2025:1759431869 2025-10-02 23:04:06
RHEL 7 ELS kernel 3.10.0 7.8 HIGH Released CLSA-2025:1759432250 2025-10-02 23:04:33
TuxCare 9.6 ESU kernel 5.14.0 7.8 HIGH Already Fixed 2025-08-18 00:47:41
Total: 14