{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ocanonicalubuntu_linux23.04/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:canonical:ubuntu_linux:23.04:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2023-2640"},{"cvss":7.8,"id":"CVE-2023-32629"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ubuntu"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","linux","kernel","overlayfs"],"_cs_type":"threat","_cs_vendors":["Canonical"],"content_html":"\u003cp\u003eResearchers have released multiple proof-of-concept (PoC) exploits targeting two linked local privilege escalation vulnerabilities in the Ubuntu kernel, identified as CVE-2023-2640 and CVE-2023-32629. These vulnerabilities stem from improper permission handling within the overlayfs (Overlay File System) implementation. Specifically, the kernel fails to perform adequate security checks when setting extended attributes (xattrs) on files using 'trusted.overlayfs.*'.\u003c/p\u003e\n\u003cp\u003eAn unprivileged local user can exploit these flaws by mounting a manipulated overlay file system, allowing them to set privileged extended attributes. This action bypasses standard kernel security mechanisms and enables the escalation of privileges to root. The vulnerabilities affect various Ubuntu releases, including 23.04, 22.10, 22.04 LTS, and 18.04 LTS, depending on the specific kernel version in use (notably 5.4.0, 5.19.0, and 6.2.0). Given the availability of weaponized PoC code on public platforms, the likelihood of exploitation by local attackers is high.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows an attacker with low-privilege local access to gain full administrative (root) control over the host system. This facilitates arbitrary code execution, complete system compromise, data exfiltration, and persistent access. All Ubuntu environments running vulnerable kernel versions are at risk if local access to the system is possible.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize patching the kernel on all affected Ubuntu systems. Consult official Canonical security bulletins for the specific kernel packages addressing these CVEs.\u003c/li\u003e\n\u003cli\u003eMonitor for the execution of unauthorized shell scripts or binaries from temporary directories, which is the observed delivery mechanism for the published PoC.\u003c/li\u003e\n\u003cli\u003eRestrict local access and enforce the principle of least privilege to minimize the potential for exploitation by unauthenticated or low-privilege users.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T00:20:53Z","date_published":"2026-08-28T00:20:53Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ubuntu-overlayfs-lpe/","summary":"Publicly available proof-of-concept exploits targeting CVE-2023-2640 and CVE-2023-32629 allow unprivileged users to gain root access on Ubuntu systems by bypassing permission checks in the overlayfs subsystem.","title":"Local Privilege Escalation in Ubuntu Kernel via OverlayFS","url":"https://feed.craftedsignal.io/briefs/2026-08-ubuntu-overlayfs-lpe/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:canonical:ubuntu_linux:23.04:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}