Executive brief
The overlayfs implementation in the Linux kernel fails to properly validate file capabilities against user namespaces. When combined with unprivileged user namespaces and specific Ubuntu kernel patches allowing unprivileged overlay mounts, a local attacker can gain elevated privileges.
Affected products
- Linux Linux Kernel Ubuntu kernel patches for unprivileged overlay mounts
Timeline
- 2021-04-16: disclosed: Public disclosure on oss-security mailing list
- 2022-10-20: kev added: Added to CISA Known Exploited Vulnerabilities Catalog