Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-2640

Description

On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.

POC

Reference

- https://wiz.io/blog/ubuntu-overlayfs-vulnerability

Github

- https://github.com/0xMarcio/cve

- https://github.com/0xWhoami35/root-kernel

- https://github.com/0xsyr0/OSCP

- https://github.com/AMatheusFeitosaM/OSCP-Cheat

- https://github.com/AlienTec1908/Run_HackMyVM_Medium

- https://github.com/Andromeda254/cve

- https://github.com/CVEDB/awesome-cve-repo

- https://github.com/CVEDB/top

- https://github.com/EnriqueSanchezdelVillar/NotesHck

- https://github.com/Ev3rPalestine/Analytics-HTB-Walkthrough

- https://github.com/Faizan-Khanx/OSCP

- https://github.com/Farhan7045/Hospital

- https://github.com/GhostTroops/TOP

- https://github.com/HaxorSecInfec/autoroot.sh

- https://github.com/K5LK/CVE-2023-2640-32629

- https://github.com/Kiosec/Linux-Exploitation

- https://github.com/Maikefee/linux-exploit-hunter

- https://github.com/Nkipohcs/CVE-2023-2640-CVE-2023-32629

- https://github.com/OllaPapito/gameoverlay

- https://github.com/PuguhDy/CVE-Root-Ubuntu

- https://github.com/ReflectedThanatos/OSCP-cheatsheet

- https://github.com/Ruhanyat-994/Ruhanyat-994

- https://github.com/SanjayRagavendar/Ubuntu-GameOver-Lay

- https://github.com/SanjayRagavendar/UbuntuPrivilegeEscalationV1

- https://github.com/SantoriuHen/NotesHck

- https://github.com/SenukDias/OSCP_cheat

- https://github.com/SirElmard/ethical_hacking

- https://github.com/Snoopy-Sec/Localroot-ALL-CVE

- https://github.com/ThrynSec/CVE-2023-32629-CVE-2023-2640---POC-Escalation

- https://github.com/Umutkgz/CVE-2023-32629-CVE-2023-2640-Ubuntu-Privilege-Escalation-POC

- https://github.com/VishuGahlyan/OSCP

- https://github.com/VladisProtas/Vulnerabilities-and-attacks-on-information-systems

- https://github.com/brimstone/stars

- https://github.com/churamanib/p0wny-shell

- https://github.com/cyberexpertsng/Cyber-Advisory

- https://github.com/druxter-x/PHP-CVE-2023-2023-2640-POC-Escalation

- https://github.com/exfilt/CheatSheet

- https://github.com/fazilbaig1/oscp

- https://github.com/filippo-zullo98/phpMyAdmin-RCE-Exploit-Lab

- https://github.com/g1vi/CVE-2023-2640-CVE-2023-32629

- https://github.com/giterlizzi/secdb-feeds

- https://github.com/ilviborici/ubuntu-privesc

- https://github.com/jitmondal1/OSCP

- https://github.com/johnlettman/juju-patch-gameoverlay

- https://github.com/johnlettman/juju-scripts

- https://github.com/k4but0/Ubuntu-LPE

- https://github.com/kaotickj/Check-for-CVE-2023-32629-GameOver-lay

- https://github.com/kgwanjala/oscp-cheatsheet

- https://github.com/luanoliveira350/GameOverlayFS

- https://github.com/musorblyat/CVE-2023-2640-CVE-2023-32629

- https://github.com/nisadevi11/Localroot-ALL-CVE

- https://github.com/nomi-sec/PoC-in-GitHub

- https://github.com/oscpname/OSCP_cheat

- https://github.com/parth45/cheatsheet

- https://github.com/revanmalang/OSCP

- https://github.com/txuswashere/OSCP

- https://github.com/vinetsuicide/CVE-2023-2640-CVE-2023-32629

- https://github.com/vlain1337/auto-lpe

- https://github.com/xS9NTX/CVE-2023-32629-CVE-2023-2640-Ubuntu-Privilege-Escalation-POC

- https://github.com/xairy/linux-kernel-exploitation

- https://github.com/xhref/OSCP

- https://github.com/zulloper/cve-poc