The OverlayFS vulnerability CVE-2023-0386: Overview, detection, and remediation
ID: 49491369-157f-5b30-9d30-00ec1976b160
STIX ID: report--49491369-157f-5b30-9d30-00ec1976b160
Feed Name: Datadog Security Labs
On March 22, 2023 CVE-2023-0386 — an OverlayFS local privilege escalation in the Linux kernel — was publicly disclosed: a trivial-to-exploit flaw (patched upstream in January 2023) allowed an unprivileged user to use a FUSE-backed lower layer and user namespaces to cause the kernel to copy a root-owned, SUID file into a world-writable upper directory (e.g., /tmp), enabling local root escalation; proof-of-concept exploits were posted in May 2023, and the report provides patch details, forensic/detection strategies (auditd, Datadog rules, file searches), and remediation guidance to upgrade kernels and monitor for unexpected SUID binaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
