Linux Kernel Improper Ownership Management Vulnerability

zetlyn/cve-kev vulnerability cve CVE-2023-0386 known 2025-06-17

Properties

cwesCWE-282
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-282
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 21:17 UTC
What the source handed over
{
  "cveID": "CVE-2023-0386",
  "cwes": "CWE-282",
  "dateAdded": "2025-06-17",
  "dueDate": "2025-07-08",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
  "product": "Kernel",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
}
due_date2025-07-08
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2025-07-08
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 21:17 UTC
What the source handed over
{
  "cveID": "CVE-2023-0386",
  "cwes": "CWE-282",
  "dateAdded": "2025-06-17",
  "dueDate": "2025-07-08",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
  "product": "Kernel",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
}
exploitedyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 21:17 UTC
What the source handed over
{
  "cveID": "CVE-2023-0386",
  "cwes": "CWE-282",
  "dateAdded": "2025-06-17",
  "dueDate": "2025-07-08",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
  "product": "Kernel",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
}
forensic_triagefalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 21:17 UTC
What the source handed over
{
  "cveID": "CVE-2023-0386",
  "cwes": "CWE-282",
  "dateAdded": "2025-06-17",
  "dueDate": "2025-07-08",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
  "product": "Kernel",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
}
known_ransomware_campaign_useUnknown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Unknown
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 21:17 UTC
What the source handed over
{
  "cveID": "CVE-2023-0386",
  "cwes": "CWE-282",
  "dateAdded": "2025-06-17",
  "dueDate": "2025-07-08",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
  "product": "Kernel",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
}
productKernel
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Kernel
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 21:17 UTC
What the source handed over
{
  "cveID": "CVE-2023-0386",
  "cwes": "CWE-282",
  "dateAdded": "2025-06-17",
  "dueDate": "2025-07-08",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
  "product": "Kernel",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
}
vendor_projectLinux
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Linux
Read by
field:vendorProject
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 21:17 UTC
What the source handed over
{
  "cveID": "CVE-2023-0386",
  "cwes": "CWE-282",
  "dateAdded": "2025-06-17",
  "dueDate": "2025-07-08",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386",
  "product": "Kernel",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.",
  "vendorProject": "Linux",
  "vulnerabilityName": "Linux Kernel Improper Ownership Management Vulnerability"
}

Text

Linux Kernel Improper Ownership Management Vulnerability Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a ; https://access.redhat.com/security/cve/cve-2023-0386 ; https://security.netapp.com/advisory/ntap-20230420-0004/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-0386