by @alchemist
04 Nov 2023

CVE-2023-0386 A Linux kernel bug in overlayfs

by @alchemist
04 Nov 2023

CVE-2023-0386 A Linux kernel bug in overlayfs

CVEs

7.8 High Severity

OS

6.12.19.*
6.12.21.*
5.4.292.*
5.4.291.*
5.4.288.*
6.12.18.*
6.12.17.*
5.15.180.*
5.10.236.*
5.10.232.*

PoC video

Summary

A Linux kernel bug in overlayfs can lead to a dangerous root privilege escalation. Overlayfs combines two layers, upper and lower, in a filesystem. Changes to lower-layer files are reflected in the upper layer, but things get tricky when upper and lower directories are in different user namespaces. By creating a lower directory in their user namespace, an attacker with fake root privileges can make a root-owned setuid binary. When this binary is copied into a world-writable directory like /tmp, it becomes a real root-owned setuid binary. This opens a pathway for running attacker-controlled code as the root user, posing a significant security risk.

Description

users/photos/clm4pm8ebnpz71gn2efjy7ime.jpg

@alchemist

70 posts

working on it.

Total vcoins

29.1K

Social media links

Comments (2)