CVE-2023-0386CISA KEVEPSS p94.0%

CVE-2023-0386Linux Kernel Improper Ownership Management Vulnerability

Linux / Kernel

Description

Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

Scoring

EPSS7.88% probability of exploitation · percentile 94.0% · 2026-06-21T12:00:28Z

CISA KEV entry

Added to KEV: 2025-06-17

(incoming)1

TypeTargetConfidenceTier
KEVEntryLinux Kernel Improper Ownership Management Vulnerabilitykev-cve-2023-03860%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Linux Kernel Privilege Escalation Vulnerability
CVE
Linux Kernel Use-After-Free Vulnerability
CVE
Linux Kernel Improper Privilege Management Vulnerability
CVE
Linux Kernel Improper Authentication Vulnerability
CVE
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
CVE
Linux Kernel Heap-Based Buffer Overflow Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.