CVE-2023-2640
HIGH 7.8EPSS 16.1%
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 16.05% chance of exploitation in the next 30 days, 97th percentile
- Nuclei
- high · CWE-863
- Published
- 2023-07-26
- Updated
- 2024-10-23
Proof-of-concept exploits (17)
- https://wiz.io/blog/ubuntu-overlayfs-vulnerability
- 0xWhoami35/root-kernel0★ · 2026-07-21
- K5LK/CVE-2023-2640-326291★ · 2024-05-22
- Nkipohcs/CVE-2023-2640-CVE-2023-326291★ · 2024-03-19
- PuguhDy/CVE-Root-Ubuntu0★ · 2024-04-04
- ThrynSec/CVE-2023-32629-CVE-2023-2640---POC-Escalation108★ · 2023-11-15
- druxter-x/PHP-CVE-2023-2023-2640-POC-Escalation0★ · 2024-02-15
- g1vi/CVE-2023-2640-CVE-2023-32629136★ · 2023-10-09
- luanoliveira350/GameOverlayFS17★ · 2023-09-17
- musorblyat/CVE-2023-2640-CVE-2023-326292★ · 2023-11-02
- vinetsuicide/CVE-2023-2640-CVE-2023-326292★ · 2023-11-02
- xS9NTX/CVE-2023-32629-CVE-2023-2640-Ubuntu-Privilege-Escalation-POC1★ · 2023-12-13
- WhatsWrongAndWhy/CVE-2023-2640-CVE-2023-32629
- amar-imamovic/CVE-2023-2640-CVE-2023-32629-Interactive-PoC
- z3usx01/CVE-2023-2640-3262-PoC
- ChouzBui897/cve-research-exploitation
- foiscs/security_project4