On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.
Fixes

Solution

No solution given by the vendor.


Workaround

If not needed, disable the ability for unprivileged users to create namespaces. To do this temporarily, do: sudo sysctl -w kernel.unprivileged_userns_clone=0 To disable across reboots, do: echo kernel.unprivileged_userns_clone=0 | \ sudo tee /etc/sysctl.d/99-disable-unpriv-userns.conf

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.91874}

epss

{'score': 0.92037}


Wed, 23 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Canonical ubantu Kernel
CPEs cpe:2.3:o:canonical:ubantu_kernel:*:*:*:*:*:*:*:*
Vendors & Products Canonical ubantu Kernel
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2024-10-23T14:59:17.779Z

Reserved: 2023-05-10T21:23:35.226Z

Link: CVE-2023-2640

cve-icon Vulnrichment

Updated: 2024-08-02T06:26:09.894Z

cve-icon NVD

Status : Modified

Published: 2023-07-26T02:15:09.300

Modified: 2024-11-21T07:58:59.060

Link: CVE-2023-2640

cve-icon Redhat

Severity : Important

Publid Date: 2023-07-06T00:00:00Z

Links: CVE-2023-2640 - Bugzilla

cve-icon OpenCVE Enrichment

No data.