Vulnerabilities > CVE-2023-2640 - Incorrect Authorization vulnerability in Canonical Ubuntu Linux 23.04
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 |