Home

Description

Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernels

PUBLISHED Reserved 2023-06-29 | Published 2023-07-26 | Updated 2025-02-13 | Assigner canonical




HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-863

Product status

Default status
unaffected

Any version before 6.2.0-26.26
unaffected

Any version before 6.0.0-1020.20
unaffected

Any version before 5.4.0-155.172
unaffected

Credits

Shir Tamari finder

Sagi Tzadik finder

References

ubuntu.com/security/notices/USN-6250-1 vendor-advisory

lists.ubuntu.com/archives/kernel-team/2023-July/140920.html mailing-list

wiz.io/blog/ubuntu-overlayfs-vulnerability technical-description

cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32629 issue-tracking

packetstormsecurity.com/...h-Security-Notice-LSN-0097-1.html

ubuntu.com/security/notices/USN-6250-1 vendor-advisory

lists.ubuntu.com/archives/kernel-team/2023-July/140920.html mailing-list

wiz.io/blog/ubuntu-overlayfs-vulnerability technical-description

cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32629 issue-tracking

packetstormsecurity.com/...h-Security-Notice-LSN-0097-1.html

cve.org (CVE-2023-32629)

nvd.nist.gov (CVE-2023-32629)

Download JSON