GameOver(lay): Easy-to-exploit local privilege escalation vulnerabilities in Ubuntu Linux affect 40% of Ubuntu cloud workloads
ID: 673e5f0a-36b3-5438-9903-e406ea43b8af
STIX ID: report--673e5f0a-36b3-5438-9903-e406ea43b8af
Feed Name: Wiz Blog
Threat Score
Wiz Research disclosed GameOver(lay), two Ubuntu-specific OverlayFS vulnerabilities (CVE-2023-2640 and CVE-2023-32629) that allow a local attacker with user-namespace and OverlayFS mount capabilities to escalate to root by copying executables with preserved file capabilities; the report includes root-cause analysis, PoC steps, affected Ubuntu kernel versions, mitigations (patches and disabling unprivileged user namespaces), and the disclosure timeline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
