CVE-2023-0386
KEVHIGH 7.8EPSS 7.9%
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 7.88% chance of exploitation in the next 30 days, 94th percentile
- CISA KEV
- added 2025-06-17
- Published
- 2023-03-22
- Updated
- 2025-10-21
Proof-of-concept exploits (26)
- 3yujw7njai/CVE-2023-03864★ · 2023-05-08
- AiK1d/CVE-2023-03864★ · 2023-05-08
- CKevens/CVE-2023-03864★ · 2023-05-08
- EstamelGG/CVE-2023-0386-libs0★ · 2024-04-23
- Fanxiaoyao66/CVE-2023-038622★ · 2023-06-28
- P4x1s/CVE-2023-03864★ · 2023-05-08
- Satheesh575555/linux-4.19.72_CVE-2023-03864★ · 2023-05-04
- chenaotian/CVE-2023-0386124★ · 2023-05-06
- churamanib/CVE-2023-03860★ · 2024-04-05
- kp18-cpu/Computer_System_Security0★ · 2025-06-21
- kp18-cpu/Vulnerability_in_suid_libraries0★ · 2025-06-20
- letsr00t/CVE-2023-03860★ · 2024-02-29
- orilevy8/cve-2023-03861★ · 2025-03-17
- puckiestyle/CVE-2023-038620★ · 2023-12-23
- ramoa1234/Rowhammer0★ · 2025-07-04
- sxlmnwb/CVE-2023-038654★ · 2023-05-16
- veritas501/CVE-2023-038610★ · 2023-04-20
- xkaneiki/CVE-2023-0386418★ · 2023-06-13
- dragosbanica/CVE-2023-0386_POC
- huovnn/CVE-2023-0386-go-poc
- pwncone/CVE-2023-0386-OverlayFS
- Anekant-Singhai/Exploits
- ChristopherPatrickKuntz/bifrost-infrastructure-disclosure
- DataDog/security-labs-pocs
- h4rithd/PrecompiledBinaries
- weto91/GitHub_Search_CVE0★ · 2026-04-27