CVE-2023-32629

HIGH EXPLOITED

Canonical Ubuntu Linux - Incorrect Authorization

Title source: rule

Description

Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernels

Exploits (9)

nomisec WORKING POC 106 stars
by ThrynSec · local
https://github.com/ThrynSec/CVE-2023-32629-CVE-2023-2640---POC-Escalation
nomisec SCANNER 9 stars
by kaotickj · poc
https://github.com/kaotickj/Check-for-CVE-2023-32629-GameOver-lay
nomisec WORKING POC 4 stars
by k4but0 · local
https://github.com/k4but0/Ubuntu-LPE
nomisec STUB 1 stars
by xS9NTX · local
https://github.com/xS9NTX/CVE-2023-32629-CVE-2023-2640-Ubuntu-Privilege-Escalation-POC
github WORKING POC 1 stars
by Shockp · pythonpoc
https://github.com/Shockp/CVE-Exploits/tree/main/CVE-2023-32629
vulncheck_xdb WORKING POC
local
https://github.com/Nkipohcs/CVE-2023-2640-CVE-2023-32629
vulncheck_xdb WORKING POC
local
https://github.com/musorblyat/CVE-2023-2640-CVE-2023-32629
vulncheck_xdb WORKING POC
local
https://github.com/luanoliveira350/GameOverlayFS
metasploit WORKING POC
by g1vi, h00die, bwatters-r7, gardnerapp · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/gameoverlay_privesc.rb

Scores

CVSS v3 7.8
EPSS 0.6284
EPSS Percentile 98.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2025-09-03
CWE
CWE-863
Status published
Products (1)
canonical/ubuntu_linux 23.04
Published Jul 26, 2023
Tracked Since Feb 18, 2026