CVE-2023-2640
HIGH EXPLOITED NUCLEIGameOver(lay) Privilege Escalation and Container Escape
Title source: metasploitDescription
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.
Exploits (14)
nomisec
WORKING POC
17 stars
by luanoliveira350 · local
https://github.com/luanoliveira350/GameOverlayFS
nomisec
WORKING POC
2 stars
by musorblyat · local
https://github.com/musorblyat/CVE-2023-2640-CVE-2023-32629
nomisec
WORKING POC
1 stars
by Nkipohcs · local
https://github.com/Nkipohcs/CVE-2023-2640-CVE-2023-32629
nomisec
WORKING POC
1 stars
by SanjayRagavendar · local
https://github.com/SanjayRagavendar/Ubuntu-GameOver-Lay
github
WORKING POC
by z3usx01 · shellpoc
https://github.com/z3usx01/CVE-2023-2640-3262-PoC/tree/main/CVE-2023-2640.sh
nomisec
WORKING POC
by filippo-zullo98 · poc
https://github.com/filippo-zullo98/phpMyAdmin-RCE-Exploit-Lab
metasploit
WORKING POC
by g1vi, h00die, bwatters-r7, gardnerapp · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/gameoverlay_privesc.rb
vulncheck_xdb
SUSPICIOUS
local
https://github.com/xS9NTX/CVE-2023-32629-CVE-2023-2640-Ubuntu-Privilege-Escalation-POC
vulncheck_xdb
WORKING POC
local
https://github.com/ThrynSec/CVE-2023-32629-CVE-2023-2640---POC-Escalation
Nuclei Templates (1)
GameOver(lay) - Local Privilege Escalation in Ubuntu Kernel
HIGHVERIFIEDby princechaddha
Shodan:
cpe:"cpe:2.3:o:canonical:ubuntu_linux"
References (4)
Scores
CVSS v3
7.8
EPSS
0.9139
EPSS Percentile
99.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2024-08-21
CWE
CWE-863
Status
published
Products (1)
canonical/ubuntu_linux
23.04
Published
Jul 26, 2023
Tracked Since
Feb 18, 2026