Exploited Vulnerabilities Daily
🌐 English

Home › Linux

CVE-2023-0386: Linux Kernel

EPSS7.8%No. 1328 of 1739 in KEV
CVE year2023~2 yrs before listing
Same vendor in KEV31
Same product31
FieldValue
VendorLinux
ProductKernel
NameLinux Kernel Improper Ownership Management Vulnerability
Added to KEV2025-06-17
US federal due date2025-07-08
Ransomware useUnknown
CWECWE-282

CISA description

Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2026-53266Linux Kernel2026-09-180.8%Unknown
CVE-2025-39964Linux Kernel2026-09-181.2%Unknown
CVE-2025-39682Linux Kernel2026-09-182.8%Unknown
CVE-2026-53362Linux Kernel2026-08-270.7%Unknown
CVE-2022-0995Linux Kernel2026-08-268.7%Unknown
CVE-2022-0492Linux Kernel2026-06-025.5%Unknown
CVE-2026-31431Linux Kernel2026-05-013.4%Unknown
CVE-2018-14634Linux Kernel2026-01-2614.6%Unknown
CVE-2021-22555Linux Kernel2025-10-0678.6%Unknown
CVE-2025-38352Linux Kernel2025-09-041.2%Unknown
CVE-2024-53197Linux Kernel2025-04-094.1%Unknown
CVE-2024-53150Linux Kernel2025-04-091.3%Unknown
CVE-2024-50302Linux Kernel2025-03-040.8%Unknown
CVE-2024-53104Linux Kernel2025-02-053.3%Unknown
CVE-2017-1000253Linux Kernel2024-09-0910.6%Known

NVD — CVE-2023-0386

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Linux Kernel vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-06-17.