High
CVE-2023-0386
PUBLISHEDA flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux...
1 day faster than CISA KEV
- Vendor
- Linux
- Product
- Linux kernel
- Published
- Mar 22, 2023
- EPSS
- 48.5% · 98% pctl
Automate this intelligence with the Pro API
Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.
Description
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.
Weaknesses (CWE)
-
Improper Ownership Management
CVSS scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation status
Exploited in the wild
Recorded 2026-06-01 13:30:39 UTC · CISA
Proof of concept available
Recorded 2023-05-05 03:02:13 UTC · GitHub
References
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a
- https://security.netapp.com/advisory/ntap-20230420-0004/
- https://www.debian.org/security/2023/dsa-5402
- https://lists.debian.org/debian-lts-announce/2023/06/msg00008.html
- http://packetstormsecurity.com/files/173087/Kernel-Live-Patch-Security-Notice-LSN-0095-1.html
- https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CVE First | 2026-06-01 10:33 UTC |
| CISA | 2026-06-02 14:07 UTC |
| Daily CyberSecurity | 2026-06-10 02:20 UTC |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/cve_2023_0386_overlayfs_priv_esc.rb | Apr 28, 2025 |
Recent mentions
Daily CyberSecurity · Jun 10, 2026
Federal Registry Alerts Enterprise Teams to Real-World Infiltration Risks The Cybersecurity and Infrastructure Security Agency updated its primary The post CISA Expands Active Exploit Catalog with Cisco, Arista, and Chromium Flaws appeared first on Daily CyberSecurity. Related posts: Linux Kernel Flaw (CVE-2023-0386) Actively Exploited for Root Privilege Escalation, PoC Available CVE-2025-23171 & CVE-2025-23172: Versa Director Bugs Open Doors to Webshell Uploads and Command Execution CISA KEV Alert: EOL D-Link and Array Networks Command Injection Under Active Attack
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2023-12-23 11:01:55 UTC · 2 stars
github · Created 2023-06-28 07:49:52 UTC · 16 stars
非常简单的CVE-2023-0386's exp and analysis.Use c and sh.
github · Created 2023-05-16 10:26:10 UTC · 40 stars
Vulnerabilities Exploitation On Ubuntu 22.04
github · Created 2023-05-06 06:07:23 UTC · 117 stars
CVE-2023-0386 analysis and Exp
github · Created 2023-05-05 03:02:13 UTC · 391 stars
CVE-2023-0386在ubuntu22.04上的提权
github · Created 2023-05-04 11:55:43 UTC · 4 stars
github · Created 2023-04-20 08:51:20 UTC · 10 stars
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Proof of Concept Exploit Available
-
Detected by Metasploit
-
Added to KEVIntel
-
KEV confirmed by CISA
-
KEV confirmed by Daily CyberSecurity