What the vulnerability does

01Description

An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.

Key dates

02Disclosure timeline

April 1, 2022 CVE published
August 3, 2024 Record updated