Local Privilege Escalation via CVE-2023-0386

zetlyn/cve-metasploit exploit cve CVE-2023-0386 known 2023-03-22

https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/cve_2023_0386_overlayfs_priv_esc.rb

Properties

platformLinux
receipt
Source
Metasploit exploit modules
Its words
Linux
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 14:04 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "x64",
  "author": [
    "xkaneiki",
    "sxlmnwb",
    "Takahiro Yokoyama"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "This exploit targets the Linux kernel bug in OverlayFS.\n\n          A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities\n          was found in the Linux kernel's OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount.\n          This uid mapping bug allows a local user to escalate their privileges on the system.",
  "disclosure_date": "2023-03-22",
  "fullname": "exploit/linux/local/cve_2023_0386_overlayfs_priv_esc",
  "is_install_path": true,
  "mod_time": "2026-05-25 09:47:44 +0000",
  "name": "Local Privilege Escalation via CVE-2023-0386",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/linux/local/cve_2023_0386_overlayfs_priv_esc.rb",
  "platform": "Linux",
  "post_auth": false,
  "rank": 600,
  "ref_name": "linux/local/cve_2023_0386_overlayfs_priv_esc",
  "references": [
    "CVE-2023-0386",
    "URL-https://github.com/sxlmnwb/CVE-2023-0386",
    "URL-https://github.com/DataDog/security-labs-pocs/tree/main/proof-of-concept-exploits/overlayfs-cve-2023-0386",
    "URL-https://securitylabs.datadoghq.com/articles/overlayfs-cve-2023-0386/",
    "URL-https://www.vicarius.io/vsociety/posts/cve-2023-0386-a-linux-kernel-bug-in-overlayfs"
  ],
  "rport": null,
  "session_types": [
    "shell",
    "meterpreter"
  ],
  "targets": [
    "Automatic"
  ],
  "type": "exploit"
}
rank600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 14:04 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "x64",
  "author": [
    "xkaneiki",
    "sxlmnwb",
    "Takahiro Yokoyama"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "This exploit targets the Linux kernel bug in OverlayFS.\n\n          A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities\n          was found in the Linux kernel's OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount.\n          This uid mapping bug allows a local user to escalate their privileges on the system.",
  "disclosure_date": "2023-03-22",
  "fullname": "exploit/linux/local/cve_2023_0386_overlayfs_priv_esc",
  "is_install_path": true,
  "mod_time": "2026-05-25 09:47:44 +0000",
  "name": "Local Privilege Escalation via CVE-2023-0386",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/linux/local/cve_2023_0386_overlayfs_priv_esc.rb",
  "platform": "Linux",
  "post_auth": false,
  "rank": 600,
  "ref_name": "linux/local/cve_2023_0386_overlayfs_priv_esc",
  "references": [
    "CVE-2023-0386",
    "URL-https://github.com/sxlmnwb/CVE-2023-0386",
    "URL-https://github.com/DataDog/security-labs-pocs/tree/main/proof-of-concept-exploits/overlayfs-cve-2023-0386",
    "URL-https://securitylabs.datadoghq.com/articles/overlayfs-cve-2023-0386/",
    "URL-https://www.vicarius.io/vsociety/posts/cve-2023-0386-a-linux-kernel-bug-in-overlayfs"
  ],
  "rport": null,
  "session_types": [
    "shell",
    "meterpreter"
  ],
  "targets": [
    "Automatic"
  ],
  "type": "exploit"
}

Text

This exploit targets the Linux kernel bug in OverlayFS. A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel's OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.