Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-32629
HistoryJun 06, 2023 - 12:00 a.m.

CVE-2023-32629

2023-06-0600:00:00
ubuntu.com
ubuntu.com
20
vulnerability
ubuntu kernels
local privilege escalation
ovl_copy_up_meta_inode_data
ovl_do_setxattr
cwe-863
wiz research
shir tamari
sagi tzadik

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

Local privilege escalation vulnerability in Ubuntu Kernels overlayfs
ovl_copy_up_meta_inode_data skip permission checks when calling
ovl_do_setxattr on Ubuntu kernels

Notes

Author Note
eslerm CWE-863 reported by Shir Tamari and Sagi Tzadik from Wiz Research
OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchlinux< 5.4.0-155.172UNKNOWN
ubuntu23.04noarchlinux< 6.2.0-26.26UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1106.114UNKNOWN
ubuntu23.04noarchlinux-aws< 6.2.0-1008.8UNKNOWN
ubuntu22.04noarchlinux-aws-5.19< 5.19.0-1029.30~22.04.1UNKNOWN
ubuntu18.04noarchlinux-aws-5.4< 5.4.0-1106.114~18.04.1UNKNOWN
ubuntu22.04noarchlinux-aws-6.2< 6.2.0-1008.8~22.04.1UNKNOWN
ubuntu20.04noarchlinux-azure< 5.4.0-1112.118UNKNOWN
ubuntu23.04noarchlinux-azure< 6.2.0-1008.8UNKNOWN
ubuntu18.04noarchlinux-azure-5.4< 5.4.0-1112.118~18.04.1UNKNOWN
Rows per page:
1-10 of 431

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%