CVE-2023-0386: Linux Kernel Improper Ownership Management Vulnerability
High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2025-06-17. EPSS: 7.9% chance of exploitation in the next 30 days.
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 20.04 only; version 22.04 only
- Debian Debian Linux: version 10.0 only
- Linux Linux Kernel: from 5.11, before 5.15.91 (fixed in 5.15.91); from 5.16, before 6.1.9 (fixed in 6.1.9); version 6.2 only
- Netapp h300s Firmware: affected versions not specified
- Netapp h410c Firmware: affected versions not specified
- Netapp h410s Firmware: affected versions not specified
- Netapp h500s Firmware: affected versions not specified
- Netapp h700s Firmware: affected versions not specified
Published 2023-03-22. Last modified 2026-06-17.