CVE-2023-2640 (GameOver(lay))

CVSS v3.1 7.8 (High)
78% Progress
EPSS 0.21 % (60th)
0.21% Progress
Affected Products 1
Advisories 4

On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.

Weaknesses
CWE-863
Incorrect Authorization
Alias
Related CVEs
CVE Status
PUBLISHED
CNA
Canonical Ltd.
Published Date
2023-07-26 02:15:09
(13 months ago)
Updated Date
2023-08-03 15:10:48
(13 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Canonical Ubuntu Linux 23.04 cpe:2.3:o:canonical:ubuntu_linux:23.04
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...