CVE-2023-0386
Linux Kernel: Improper Ownership Management
As of , CVE-2023-0386 in Linux Kernel is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 17 June 2025
- US federal deadline
- 8 July 202521 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.08Higher than 94% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- Public exploit
- 1 Metasploit module
- Fix
- Vendor advice: access.redhat.com, git.kernel.org and security.netapp.comLinks below, from CISA's entry.
What CISA says to do
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA's required action
- git.kernel.orgThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more…
- access.redhat.com
- security.netapp.com
What the flaw is
Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.
CISA's description
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.
The CVE record's description, from redhat
- CVE published
- 22 March 2023
- Assigned by
- redhat
- CVSS
- 7.8 High (CVSS 3.1, from CISA-ADP)
- CWE-282
- Improper Ownership Management
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: Local Privilege Escalation via CVE-2023-0386exploit module, rank excellent
Kernel: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-39682Improper Check for Unusual or Exceptional Conditions | Linux Kernel | Patch nowForensic triage required by CISA | 0.03 | ||
| CVE-2025-39964Race Condition | Linux Kernel | Patch nowForensic triage required by CISA | 0.01 | ||
| CVE-2026-53266Out-of-Bounds Write | Linux Kernel | Patch nowForensic triage required by CISA | 0.01 | ||
| CVE-2026-53362Unspecified | Linux Kernel | Patch nowForensic triage required by CISA | 0.01 | ||
| CVE-2021-22555Heap Out-of-Bounds Write | Linux Kernel | Patch this weekMetasploit module; EPSS 0.79; verified Exploit-DB entry | 0.79 | ||
| CVE-2013-6282Improper Input Validation | Linux Kernel | Patch this weekMetasploit module; verified Exploit-DB entry | 0.40 | ||
| CVE-2019-13272Improper Privilege Management | Linux Kernel | Patch this weekMetasploit module; EPSS 0.52; verified Exploit-DB entry | 0.52 | ||
| CVE-2010-3904Improper Input Validation | Linux Kernel | Patch this weekMetasploit module; verified Exploit-DB entry | 0.16 | ||
| CVE-2022-0847Privilege Escalation | Linux Kernel | Patch this weekMetasploit module; EPSS 0.93 | 0.93 | ||
| CVE-2021-3493Privilege Escalation | Linux Kernel | Patch this weekMetasploit module | 0.49 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org