A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.
Lab | Machine | Link |
---|---|---|
Hack The Box | TwoMillion | Go to Practice |
References:
https://nvd.nist.gov/vuln/detail/CVE-2023-0386