⚠ Actively exploited
Added to CISA KEV on 2025-06-17. Federal agencies required to patch by 2025-07-08. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable..

CVE-2023-0386Improper Ownership Management in Kernel

Severity
7.8HIGHNVD
EPSS
49.2%
top 2.22%
CISA KEV
KEV
Added 2025-06-17
Due 2025-07-08
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMar 22
KEV addedJun 17
Latest updateJun 18
KEV dueJul 8
CISA Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDlinux/linux_kernel5.115.15.91+2
Debianlinux/linux_kernel< 5.10.179-1+3
Ubuntulinux/linux_kernel< 5.4.0-150.167+1
CVEListV5linux/linux_kernelLinux kernel 6.2-rc6

Also affects: Debian Linux 10.0, Ubuntu Linux 18.04, 20.04, 22.04

Patches

🔴Vulnerability Details

9
GHSA
GHSA-p72q-v88c-rprq: A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s2023-07-06
OSV
Kernel Live Patch Security Notice2023-06-21
OSV
linux-intel-iotg vulnerabilities2023-05-05
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.19, linux-ibm, linux-kvm, linux-lowlatency, linux-oracle, linux-raspi vulnerabilities2023-04-26
OSV
linux-hwe-5.15 vulnerabilities2023-04-25

💥Exploits & PoCs

1
Metasploit
Local Privilege Escalation via CVE-2023-0386

📋Vendor Advisories

12
CISA
Linux Kernel Improper Ownership Management Vulnerability2025-06-17
Ubuntu
Kernel Live Patch Security Notice2023-06-21
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2023-06-01
Ubuntu
Linux kernel (OEM) vulnerabilities2023-05-10
Ubuntu
Linux kernel (OEM) vulnerabilities2023-05-10

🕵️Threat Intelligence

1
Bleepingcomputer
CISA warns of attackers exploiting Linux flaw with PoC exploit2025-06-18

💬Community

1
Bugzilla
CVE-2023-0386 kernel: FUSE filesystem low-privileged user privileges escalation2023-01-09
CVE-2023-0386 — Improper Ownership Management in Kernel | cvebase