On June 18, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added the Linux kernel vulnerability CVE‑2023‑0386 to its Known Exploited Vulnerabilities (KEV) Catalog. This inclusion follows confirmed reports of active exploitation in the wild, posing a serious threat to exposed systems.

With a CVSS score of 7.8, the vulnerability stems from an “improper ownership management” issue in the OverlayFS subsystem of the Linux kernel. It allows attackers to escalate privileges by tricking the system into spawning SUID binaries — executables that run with elevated privileges, specifically root

How the Exploit Works

OverlayFS facilitates union mounting of disparate directories, allowing the kernel to manage file systems in layers. According to CISA:

“Linux kernel contains an improper ownership management vulnerability … in how a user copies a capable file from a nosuid mount into another mount.”

Security firm Datadog illustrated the mechanism back in May 2023. The exploit enables an unprivileged user to:

  1. Copy a capable file (with setuid bits) from the lower layer (nosuid-disabled).
  2. Move it into an upper layer, bypassing proper ownership checks.
  3. Execute it from a directory like /tmp, where the file appears to be owned by root.
  4. Achieve local root access, compromising the system

In simple terms, the attacker “smuggles” a privileged binary into a writable location, then runs it to take over the host .


Historical Context: Related Vulnerabilities

OverlayFS has been the source of similar exploits in the past. In mid-2023, Wiz, a cloud security firm, disclosed two related flaws—GameOver(lay)—affecting Ubuntu and enabling analogous privilege elevation techniques (CVE‑2023‑32629 and CVE‑2023‑2640). These exploits, too, manipulated OverlayFS to create unauthorized SUID executables for root privilege escalation.

Who Is at Risk?

While any Linux system using OverlayFS could be vulnerable, those employing user namespaces and container technologies (like Docker, Kubernetes, or certain chroot environments) are particularly at risk. As noted by both Datadog and Wiz, the flaw is “trivial to exploit”, meaning even users with minimal privileges can leverage it to gain full system control

CISA’s Urgent Advisory for Federal Agencies

CISA has mandated that all Federal Civilian Executive Branch (FCEB) agencies must:

  • Apply the official Linux kernel patch for CVE‑2023‑0386.
  • Comply by July 8, 2025, to mitigate active threats

This directive underscores the severity of the issue. Federal systems are frequently targeted by sophisticated attackers; delaying patching increases exposure to compromise.

Mitigation Steps for All Users

Even outside U.S. federal systems, any Linux environment using OverlayFS should act immediately:

  1. Update your Linux kernel to a version patched in early 2023.
  2. Verify patched OverlayFS behavior via official kernel changelogs or vendor advisories.
  3. Restrict untrusted user namespaces, especially in environments like Docker or Kubernetes where users may have container-level access.
  4. Audit systems for suspicious SUID binaries located in common writeable directories like /tmp.
  5. Use least privilege principles — ensure only essential users/groups have access to OverlayFS mounts and user namespaces.

Failing to patch risks full system compromise with local exploits, data theft, or deployment of further malicious tools.

Why This Matters

CVE‑2023‑0386 exemplifies a stealthy yet potent vulnerability: it doesn’t need network access, only local execution rights, which are easier for attackers to obtain. OverlayFS is widely used; thus, the exploit’s attack surface is extensive. The ease of attack and potential for total system takeover make it a high-priority issue.

Furthermore, Container-driven infrastructure means enterprise and cloud systems are not exempt. Misconfigurations or oversights can allow attackers to escalate from isolated containers to full host compromise.

Final Takeaway

CVE‑2023‑0386 is a tangible, actively exploited vulnerability that demands immediate attention. Whether you’re a federal agency, enterprise, or small business, taking prompt action is essential:

  • Patch your Linux kernel now to versions addressing CVE‑2023‑0386.
  • Enforce overlay namespace restrictions to limit exposure.
  • Audit and monitor for unauthorized SUID file creations.

Ignoring this advisory could leave critical systems open to root-level breaches via a mechanic that’s straightforward to exploit. Stay proactive, secure your infrastructure, and keep OverlayFS-managed environments under scrutiny.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *