Improper Ownership Management Affecting torvalds/linux package, versions [2.6.12-rc2, 6.2-rc6)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
19.04% (95th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-TORVALDSLINUX-5926775
  • published2 Oct 2023
  • disclosed13 Jan 2023
  • creditD. E. Shaw Group

Introduced: 13 Jan 2023

CVE-2023-0386  (opens in a new tab)
CWE-282  (opens in a new tab)

How to fix?

Upgrade torvalds/linux to version 6.2-rc6 or higher.

Overview

Affected versions of this package are vulnerable to Improper Ownership Management due to unauthorised access to the execution of the setuid file in the OverlayFS subsystem, allowing a user to copy a capable file from a nosuid mount into another mount.

Note: This uid mapping bug allows a local user to escalate their privileges on the system.

References

CVSS Base Scores

version 3.1