Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-0386

78
FAUCET Score

CVE-2023-0386 is a critical privilege escalation vulnerability in the Linux kernel's OverlayFS subsystem, affecting Canonical, Debian, Linux, and NetApp products. This flaw allows a local user to gain root privileges by exploiting a uid mapping bug when copying a capable file from a nosuid mount. With a CVSS score of 7.8 (High), the vulnerability is easily exploitable with low attack complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. This CVE is actively exploited in the wild, has a Metasploit module available, and has garnered significant community discussion and media coverage, indicating its widespread impact and urgency.

Impacted Technologies

VendorProductVersion(s)CPE
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
7.88%
Probability of exploitation in next 30 days
EPSS Percentile
94.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Jun 17, 2025
Metasploit: Local Privilege Escalation via CVE-2023-0386 · Mar 22, 2023
This CVE's current EPSS score of 0.0788 is in the 99th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (22)

microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 5.15.107.1-2
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 5.15.107.1-2
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 5.10.188.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 5.10.185.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 5.10.188.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 5.10.185.1-1
microsoftpatch availablevia msrc
Product: cm1 hyperv-daemons 5.10.188.1-1 on CBL Mariner 1.0Fixed in: 5.10.188.1-1
microsoftpatch availablevia msrc
Product: cm1 kernel 5.10.185.1-1 on CBL Mariner 1.0Fixed in: 5.10.185.1-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.107.1-2 on CBL Mariner 2.0Fixed in: 5.15.107.1-2
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: kernel-0:4.18.0-372.51.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-162.23.1.el9_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt-0:5.14.0-162.23.1.rt21.186.el9_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: kernel-0:5.14.0-70.53.1.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: kernel-rt-0:5.14.0-70.53.1.rt21.124.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-372.51.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: redhat-virtualization-host-0:4.5.3-202304051438_8.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-425.19.2.rt7.230.el8_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-425.19.2.el8_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kpatch-patch
View patch

Vendor Advisories (4)

microsoft2023-May/CVE-2023-0386

CVE-2023-0386

May 9, 2023
linuxCVE-2023-0386HIGH

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

Mar 22, 2023
microsoft2023-Mar/CVE-2023-0386Important

A flaw was found in the Linux kernel where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

Mar 14, 2023
redhatCVE-2023-0386Important

kernel: FUSE filesystem low-privileged user privileges escalation

Jan 24, 2023

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
packetstormsecurity.com / files/173087/Kernel-Live-Patch-Security-Notice-LSN-0095-1.html
Third Party Advisory
git.kernel.org / pub/scm/linux/kernel/git/torvalds/linux.git/commit
Broken LinkMailing ListPatchVendor Advisory
lists.debian.org / debian-lts-announce/2023/06/msg00008.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2024/06/msg00020.html
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20230420-0004
Third Party Advisory
debian.org / security/2023/dsa-5402
Third Party Advisory