by @alchemist
04 Nov 2023

CVE-2023-0386 A Linux kernel bug in overlayfs

by @alchemist
04 Nov 2023

CVE-2023-0386 A Linux kernel bug in overlayfs

CVEs

7.8 High Severity

OS

4.19.322.*
5.4.284.*
6.1.108.*
5.15.155.*
5.4.283.*
4.19.321.*
5.15.167.*
5.15.165.*
6.1.107.*
5.12.25.*

PoC video

Summary

A Linux kernel bug in overlayfs can lead to a dangerous root privilege escalation. Overlayfs combines two layers, upper and lower, in a filesystem. Changes to lower-layer files are reflected in the upper layer, but things get tricky when upper and lower directories are in different user namespaces. By creating a lower directory in their user namespace, an attacker with fake root privileges can make a root-owned setuid binary. When this binary is copied into a world-writable directory like /tmp, it becomes a real root-owned setuid binary. This opens a pathway for running attacker-controlled code as the root user, posing a significant security risk.

Description

users/photos/clm4pm8ebnpz71gn2efjy7ime.jpg

@alchemist

59 posts

working on it.

Total vcoins

25.3K

Social media links

Comments (2)