Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernels

Project Subscriptions

Vendors Products
Canonical Subscribe
Ubantu Kernel Subscribe
Ubuntu Linux Subscribe
Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-6248-1 Linux kernel (OEM) vulnerabilities
Ubuntu USN Ubuntu USN USN-6250-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6251-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6260-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6261-1 Linux kernel (IoT) vulnerabilities
Ubuntu USN Ubuntu USN USN-6285-1 Linux kernel (OEM) vulnerabilities
Ubuntu USN Ubuntu USN USN-8255-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8255-2 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8255-3 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8275-1 Linux kernel (Xilinx ZynqMP) vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

If not needed, disable the ability for unprivileged users to create namespaces. To do this temporarily, do: sudo sysctl -w kernel.unprivileged_userns_clone=0 To disable across reboots, do: echo kernel.unprivileged_userns_clone=0 | \ sudo tee /etc/sysctl.d/99-disable-unpriv-userns.conf

History

Wed, 23 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Canonical ubantu Kernel
CPEs cpe:2.3:o:canonical:ubantu_kernel:*:*:*:*:*:*:*:*
Vendors & Products Canonical ubantu Kernel
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2025-02-13T16:54:52.620Z

Reserved: 2023-06-29T21:43:35.022Z

Link: CVE-2023-32629

cve-icon Vulnrichment

Updated: 2024-08-02T15:25:36.941Z

cve-icon NVD

Status : Modified

Published: 2023-07-26T02:15:09.413

Modified: 2024-11-21T08:03:44.193

Link: CVE-2023-32629

cve-icon Redhat

Severity : Important

Publid Date: 2023-07-06T00:00:00Z

Links: CVE-2023-32629 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses