CVE-2023-32629

Severity
7.8HIGH
EPSS
62.8%
top 1.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 26
Latest updateSep 5

Description

Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernels

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages36 packages

Ubuntulinux< 5.4.0-155.172
Ubuntulinux-aws< 5.4.0-1106.114
Ubuntulinux-gcp< 5.4.0-1109.118
Ubuntulinux-gke< 5.4.0-1104.111
Ubuntulinux-ibm< 5.4.0-1053.58

Also affects: Ubuntu Linux 23.04

Patches

🔴Vulnerability Details

5
OSV
linux-iot vulnerabilities2023-07-28
CVEList
CVE-2023-32629: Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr o2023-07-26
GHSA
GHSA-5xvw-32xh-2vr5: Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr o2023-07-26
OSV
CVE-2023-32629: Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr o2023-06-06
VulnCheck
canonical ubuntu_linux Incorrect Authorization2023

🔍Detection Rules

1
Elastic
Potential Privilege Escalation via OverlayFS

📋Vendor Advisories

9
Ubuntu
Kernel Live Patch Security Notice2023-09-05
Ubuntu
Linux kernel (OEM) vulnerabilities2023-08-11
Ubuntu
Linux kernel (IoT) vulnerabilities2023-07-28
Ubuntu
Linux kernel vulnerabilities2023-07-27
Ubuntu
Linux kernel vulnerabilities2023-07-26

🕵️Threat Intelligence

3
Wiz
Crying Out Cloud - July Newsletter | Wiz2023-08-01
Wiz
GameOverlay Vulnerability Impacts 40% of Ubuntu Workloads | Wiz Blog2023-07-27
Wiz
GameOverlay Vulnerability Impacts 40% of Ubuntu Workloads | Wiz Blog2023-07-27
CVE-2023-32629 (HIGH CVSS 7.8) | Local privilege escalation vulnerab | cvebase.io