Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2023-2640Incorrect Authorization in Ubuntu Linux

Severity
7.8HIGHNVD
EPSS
91.5%
top 0.33%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJul 26
Latest updateAug 11

Description

On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages0 packages

Also affects: Ubuntu Linux 23.04

Patches

🔴Vulnerability Details

6
OSV
linux-oem-6.1 vulnerabilities2023-08-11
GHSA
GHSA-38f7-vv5r-859m: On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted2023-07-26
CVEList
CVE-2023-2640: On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted2023-07-26
OSV
linux-oem-6.0 vulnerabilities2023-07-25
OSV
CVE-2023-2640: On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted2023-06-06

💥Exploits & PoCs

1
Nuclei
GameOver(lay) - Local Privilege Escalation in Ubuntu Kernel

🔍Detection Rules

1
Elastic
Potential Privilege Escalation via OverlayFS

📋Vendor Advisories

7
Ubuntu
Linux kernel (OEM) vulnerabilities2023-08-11
Ubuntu
Linux kernel vulnerabilities2023-07-27
Ubuntu
Linux kernel (OEM) vulnerabilities2023-07-25
Ubuntu
Linux kernel vulnerabilities2023-07-25
Red Hat
kernel: overlayfs: In Ubuntu skip permission checking for trusted.overlayfs.* xattrs2023-07-06

🕵️Threat Intelligence

3
Wiz
Crying Out Cloud - July Newsletter | Wiz2023-08-01
Wiz
GameOverlay Vulnerability Impacts 40% of Ubuntu Workloads | Wiz Blog2023-07-27
Wiz
GameOverlay Vulnerability Impacts 40% of Ubuntu Workloads | Wiz Blog2023-07-27
CVE-2023-2640 — Incorrect Authorization in Ubuntu Linux | cvebase