CVE-2023-0386

HIGH KEV

Local Privilege Escalation via CVE-2023-0386

Title source: metasploit

Description

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

Exploits (17)

nomisec WORKING POC 412 stars
by xkaneiki · local
https://github.com/xkaneiki/CVE-2023-0386
nomisec WORKING POC 123 stars
by chenaotian · local
https://github.com/chenaotian/CVE-2023-0386
nomisec WORKING POC 49 stars
by sxlmnwb · local
https://github.com/sxlmnwb/CVE-2023-0386
nomisec WORKING POC 19 stars
by Fanxiaoyao66 · local
https://github.com/Fanxiaoyao66/CVE-2023-0386
nomisec WORKING POC 12 stars
by puckiestyle · local
https://github.com/puckiestyle/CVE-2023-0386
nomisec WORKING POC 10 stars
by veritas501 · local
https://github.com/veritas501/CVE-2023-0386
nomisec WORKING POC 4 stars
by P4x1s · poc
https://github.com/P4x1s/CVE-2023-0386
nomisec WRITEUP 4 stars
by Satheesh575555 · poc
https://github.com/Satheesh575555/linux-4.19.72_CVE-2023-0386
nomisec WORKING POC 1 stars
by orilevy8 · local
https://github.com/orilevy8/cve-2023-0386
nomisec WRITEUP
by karimelsheikh1 · poc
https://github.com/karimelsheikh1/HTB-TwoMillion-Writeup
nomisec WORKING POC
by huovnn · local
https://github.com/huovnn/CVE-2023-0386-go-poc
nomisec WORKING POC
by dragosbanica · local
https://github.com/dragosbanica/CVE-2023-0386_POC
nomisec WORKING POC
by EstamelGG · local
https://github.com/EstamelGG/CVE-2023-0386-libs
nomisec WORKING POC
by churamanib · local
https://github.com/churamanib/CVE-2023-0386
nomisec STUB
by letsr00t · poc
https://github.com/letsr00t/CVE-2023-0386
metasploit WORKING POC EXCELLENT
by xkaneiki, sxlmnwb, Takahiro Yokoyama · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/cve_2023_0386_overlayfs_priv_esc.rb

Scores

CVSS v3 7.8
EPSS 0.5298
EPSS Percentile 98.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2025-06-17
VulnCheck KEV 2025-06-17
ENISA EUVD EUVD-2023-12447
CWE
CWE-282
Status published
Products (11)
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 20.04
canonical/ubuntu_linux 22.04
debian/debian_linux 10.0
linux/linux_kernel 6.2 rc1 (5 CPE variants)
linux/linux_kernel 5.11 - 5.15.91
netapp/h300s_firmware
netapp/h410c_firmware
netapp/h410s_firmware
netapp/h500s_firmware
... and 1 more
Published Mar 22, 2023
KEV Added Jun 17, 2025
Tracked Since Feb 18, 2026