Description
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernels
Problem types
Product status
Any version before 6.2.0-26.26
Any version before 6.0.0-1020.20
Any version before 5.4.0-155.172
Credits
Shir Tamari
Sagi Tzadik
References
ubuntu.com/security/notices/USN-6250-1
lists.ubuntu.com/archives/kernel-team/2023-July/140920.html
wiz.io/blog/ubuntu-overlayfs-vulnerability
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32629
packetstormsecurity.com/...h-Security-Notice-LSN-0097-1.html
ubuntu.com/security/notices/USN-6250-1
lists.ubuntu.com/archives/kernel-team/2023-July/140920.html
wiz.io/blog/ubuntu-overlayfs-vulnerability
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32629
packetstormsecurity.com/...h-Security-Notice-LSN-0097-1.html