Linux Kernel Improper Ownership Management Vulnerability

Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

Published 4 Aug 2026Updated 4 Aug 202621 sources
CVSS 0.0 PoC CANDIDATE△ CISA KEV

What happened

Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

Affected versions

Kernel: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
PoC-in-GitHub · veritas501/CVE-2023-0386★ 10veritas5012023-04-20CandidatePoC-in-GitHub · Satheesh575555/linux-4.19.72_CVE-2023-0386★ 4Satheesh5755552023-05-04CandidatePoC-in-GitHub · xkaneiki/CVE-2023-0386CVE-2023-0386在ubuntu22.04上的提权★ 419xkaneiki2023-05-05CandidatePoC-in-GitHub · chenaotian/CVE-2023-0386CVE-2023-0386 analysis and Exp★ 124chenaotian2023-05-06CandidatePoC-in-GitHub · P4x1s/CVE-2023-0386CVE-2023-0386 EXP★ 4P4x1s2023-05-08CandidatePoC-in-GitHub · sxlmnwb/CVE-2023-0386Vulnerabilities Exploitation On Ubuntu 22.04★ 54sxlmnwb2023-05-16CandidatePoC-in-GitHub · Fanxiaoyao66/CVE-2023-0386非常简单的CVE-2023-0386's exp and analysis.Use c and sh.★ 22Fanxiaoyao662023-06-28CandidatePoC-in-GitHub · puckiestyle/CVE-2023-0386★ 21puckiestyle2023-12-23CandidatePoC-in-GitHub · letsr00t/CVE-2023-0386★ 0letsr00t2024-02-29CandidatePoC-in-GitHub · churamanib/CVE-2023-0386★ 0churamanib2024-04-05CandidatePoC-in-GitHub · EstamelGG/CVE-2023-0386-libsCVE-2023-0386 包含所需运行库★ 0EstamelGG2024-04-22CandidatePoC-in-GitHub · orilevy8/cve-2023-0386★ 1orilevy82025-03-17CandidatePoC-in-GitHub · dragosbanica/CVE-2023-0386_POC★ 0dragosbanica2026-01-20CandidatePoC-in-GitHub · huovnn/CVE-2023-0386-go-poc★ 0huovnn2026-02-07CandidatePoC-in-GitHub · karimelsheikh1/HTB-TwoMillion-WriteupHackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386★ 0karimelsheikh12026-04-23CandidatePoC-in-GitHub · julianertle/CVE-2023-0386-CTF★ 0julianertle2026-05-20CandidatePoC-in-GitHub · anxs3c/TwoMillion-Machine-WriteupFrom deobfuscating code.js to root, CVE-2023-0386★ 0anxs3c2026-06-11CandidatePoC-in-GitHub · pwncone/CVE-2023-0386-OverlayFSCopy fake in-memory files to disk using overlayFS★ 0pwncone2026-06-28CandidatePoC-in-GitHub · abedallarawashdeh/HTB-TwoMillion-machineHack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.★ 0abedallarawashdeh2026-08-05Candidate