Impact
The Linux kernel contained a missing Landlock guard that allowed an unprivileged local user to create or move whiteout objects within an OverlayFS mount. Whiteouts are used to represent deleted files in the upper layer of an overlay, and when forged or relocated they can re‑establish a file name that no longer exists in the lower layer, effectively hiding or overriding data visible to processes inside that overlay environment. This manipulation enables a local attacker to alter the unified view of a filesystem, potentially exposing or conce flaw is mapped to the access‑control weakness class CWE‑1220.
Affected Systems
All Linux kernel installations that expose the OverlayFS feature—both the built‑in kernel overlay and the user‑space fuse‑overlayfs. No specific product or version list is available, so administrators should treat all unpatched kernel releases as affected.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity vulnerability that can be exploited locally. The EPSS score of less than 1% and its absence from the CISA KEV catalog suggest that active exploitation is currently uncommon, but the flaw’s local nature and lack of a privileged requirement mean that any user who can write to an OverlayFS mount point can prepare the exploit. Successful exploitation requires invoking mknod(2) with S_IFCHR or renameat2(2) with RENAME_WHITEOUT, which are user‑space operations that can be performed by processes already executing with the same privileges that own the overlay mount.
OpenCVE Enrichment
Debian DSA