CVE-2023-0386CISA KEV: Actively Exploited

Linux Kernel Improper Ownership Management Vulnerability

Published Jun 17, 2025·Updated Jun 17, 2025

Description

Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

Public Exploits & PoCs9 found

PoC: CVE-2023-0386

CVE-2023-0386 EXP

1

[POC] MAL-2026-2307 — CVE-2023-0386-OverlayFS

Copy fake in-memory files to disk using overlayFS

PoC: TwoMillion-Machine

From deobfuscating code.js to popping root with CVE-2023-0386. Covers invite code generation, API endpoint discovery, lateral movement, admin privilege escalation, OS command injection, www-data shell, .env credential reuse, SSH as admin, and kernel exploitation

PoC: HTB-TwoMillion-Writeup

HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386

PoC: CVE-2023-0386-libs

CVE-2023-0386 包含所需运行库

PoC: CVE-2023-0386

非常简单的CVE-2023-0386's exp and analysis.Use c and sh.

PoC: CVE-2023-0386

Vulnerabilities Exploitation On Ubuntu 22.04

PoC: CVE-2023-0386

CVE-2023-0386 analysis and Exp

PoC: CVE-2023-0386

CVE-2023-0386在ubuntu22.04上的提权

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free