Description Preview
Overview
The vulnerability exists in the OverlayFS subsystem of the Linux kernel. OverlayFS is a type of union filesystem that allows overlaying one filesystem on top of another. The specific issue involves how the kernel handles the copying of files with capabilities from nosuid mounts to other mounts. When a user copies a capable file from a nosuid mount to another mount, the uid mapping is incorrectly handled, allowing the preservation of capabilities that should be dropped. This improper permission management (CWE-282) enables local users to execute setuid files with elevated privileges, effectively bypassing security restrictions intended to prevent privilege escalation.
Remediation
To mitigate this vulnerability, system administrators should:
-
Update the Linux kernel to a patched version. The fix has been committed to the mainline Linux kernel (commit 4f11ada10d0a).
-
For specific distributions:
- Debian users should apply the security updates referenced in DSA-5402 for standard Debian or DLA 3446-1/DLA 3840-1 for Debian LTS.
- Other Linux distributions should apply their respective vendor-provided security patches.
-
If immediate patching is not possible, consider implementing additional access controls to restrict local user access to sensitive file systems and monitor for suspicious file operations involving setuid files.
-
After patching, restart the system to ensure the updated kernel is in use.
References
- Linux Kernel Fix: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a
- Debian Security Advisory: https://www.debian.org/security/2023/dsa-5402
- Debian LTS Announcement: https://lists.debian.org/debian-lts-announce/2023/06/msg00008.html
- Debian LTS Announcement (2024): https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html
- NetApp Security Advisory: https://security.netapp.com/advisory/ntap-20230420-0004/
- Kernel Live Patch Security Notice: http://packetstormsecurity.com/files/173087/Kernel-Live-Patch-Security-Notice-LSN-0095-1.html
Early Warning
Customers using Armis Early Warning were notified about this vulnerability before it appeared in CISA's Known Exploited Vulnerabilities Catalog, enabling them to assess their exposure and act proactively. Armis offers these examples of CVEs already included in CISA KEV for potential customers. Click here to learn how to receive alerts earlier.
- Armis Alert Date
- Mar 22, 2023
- CISA KEV Date
- Jun 17, 2025
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing: Medium
- Health Care & Social AssistanceHealth Care & Social Assistance: Medium
- Public AdministrationPublic Administration: Medium
- Finance and InsuranceFinance and Insurance: Low
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services: Low
- Transportation & WarehousingTransportation & Warehousing: Low
- Retail TradeRetail Trade: Low
- Arts, Entertainment & RecreationArts, Entertainment & Recreation: Low
- Educational ServicesEducational Services: Low
- Management of Companies & EnterprisesManagement of Companies & Enterprises: Low
- Other Services (except Public Administration)Other Services (except Public Administration): Low
- UtilitiesUtilities: Low
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting: Low
- Real Estate Rental & LeasingReal Estate Rental & Leasing: Low
- Accommodation & Food ServicesAccommodation & Food Services: Low
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services: Low
- ConstructionConstruction: Low
- InformationInformation: Low
- MiningMining: Low
- Wholesale TradeWholesale Trade: Low