Back

HIGH

kernel: overlayfs: In Ubuntu skip permission checking for trusted.overlayfs.* xattrs

Published Jul 26, 2023

Description

On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.

Affected products

Remediation

Vendor solution

If not needed, disable the ability for unprivileged users to create namespaces. To do this temporarily, do: sudo sysctl -w kernel.unprivileged_userns_clone=0 To disable across reboots, do: echo kernel.unprivileged_userns_clone=0 | \ sudo tee /etc/sysctl.d/99-disable-unpriv-userns.conf

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Jul 26, 2023
Updated Oct 23, 2024
Reserved May 10, 2023
CISA Vulnrichment
Updated Oct 23, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 6, 2023