CVE-2023-32629
HIGH EXPLOITEDCanonical Ubuntu Linux - Incorrect Authorization
Title source: ruleDescription
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernels
Exploits (9)
nomisec
WORKING POC
106 stars
by ThrynSec · local
https://github.com/ThrynSec/CVE-2023-32629-CVE-2023-2640---POC-Escalation
nomisec
SCANNER
9 stars
by kaotickj · poc
https://github.com/kaotickj/Check-for-CVE-2023-32629-GameOver-lay
nomisec
STUB
1 stars
by xS9NTX · local
https://github.com/xS9NTX/CVE-2023-32629-CVE-2023-2640-Ubuntu-Privilege-Escalation-POC
github
WORKING POC
1 stars
by Shockp · pythonpoc
https://github.com/Shockp/CVE-Exploits/tree/main/CVE-2023-32629
metasploit
WORKING POC
by g1vi, h00die, bwatters-r7, gardnerapp · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/gameoverlay_privesc.rb
References (5)
Scores
CVSS v3
7.8
EPSS
0.6284
EPSS Percentile
98.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2025-09-03
CWE
CWE-863
Status
published
Products (1)
canonical/ubuntu_linux
23.04
Published
Jul 26, 2023
Tracked Since
Feb 18, 2026