GameOver(lay): Zwei schwerwiegende Linux-Schwachstellen betreffen 40% der Ubuntu-Nutzer

Teilen:

Cybersecurity-Forscher haben zwei schwerwiegende Sicherheitslücken im Ubuntu-Kernel aufgedeckt, die den Weg für lokale Angriffe zur Privilegienerweiterung ebnen könnten.

Cloud security firm Wiz, in a report shared with The Hacker News, said the easy-to-exploit shortcomings have the potential to impact 40% of Ubuntu users.

The impacted Ubuntu versions are prevalent in the cloud as they serve as the default operating systems for multiple [cloud service providers], security researchers Sagi Tzadik and Shir Tamari said.

The vulnerabilities – tracked as CVE-2023-2640 and CVE-2023-32629 (CVSS scores: 7.8) and dubbed GameOver(lay) – are present in a module called OverlayFS and arise as a result of inadequate permissions checks in certain scenarios, enabling a local attacker to gain elevated privileges.

Overlay Filesystem refers to a union mount file system that makes it possible to combine multiple directory trees or file systems into a single, unified file system.

A brief description of the two flaws is below –

CVE-2023-2640 – On Ubuntu kernels carrying both c914c0e27eb0 and UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs, an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.
CVE-2023-32629 – Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernels.

In a nutshell, GameOver(lay) makes it possible to craft an executable file with scoped file capabilities and trick the Ubuntu Kernel into copying it to a different location with unscoped capabilities, granting anyone who executes it root-like privileges.

Following responsible disclosure, the vulnerabilities have been fixed by Ubuntu as of July 24, 2023.

The findings underscore the fact that subtle changes in the Linux kernel introduced by Ubuntu could have unforeseen implications, Wiz CTO and co-founder Ami Luttwak said in a statement shared with the publication.

Both vulnerabilities are unique to Ubuntu kernels since they stemmed from Ubuntu’s individual changes to the OverlayFS module, the researchers said, adding the issues are comparable to other vulnerabilities such as CVE-2016-1576, CVE-2021-3493, CVE-2021-3847, and CVE-2023-0386.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:16 am, Juni 3, 2025
Wetter-Symbol 13°C
L: 12° | H: 14°
wenige Wolken
Luftfeuchtigkeit: 62 %
Druck: 1012 mb
Wind: 8 mph SSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 19%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:47 am
Sonnenuntergang: 9:10 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
12° | 14°°C 1 mm 100% 16 mph 92 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
10° | 17°°C 0.47 mm 47% 12 mph 84 % 1009 mb 0 mm/h
Do. Juni 05 10:00 pm
Wetter-Symbol
12° | 19°°C 0.76 mm 76% 12 mph 88 % 1008 mb 0 mm/h
Fr. Juni 06 10:00 pm
Wetter-Symbol
12° | 17°°C 1 mm 100% 11 mph 96 % 1008 mb 0 mm/h
Sa. Juni 07 10:00 pm
Wetter-Symbol
11° | 18°°C 1 mm 100% 18 mph 95 % 1007 mb 0 mm/h
Today 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 9 mph 62 % 1013 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 11 mph 66 % 1012 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
14° | 15°°C 0 mm 0% 14 mph 67 % 1010 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 16 mph 76 % 1007 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
14° | 14°°C 1 mm 100% 14 mph 92 % 1007 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
14° | 14°°C 1 mm 100% 9 mph 89 % 1007 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
16° | 16°°C 1 mm 100% 8 mph 58 % 1007 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
14° | 14°°C 0 mm 0% 7 mph 59 % 1009 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,589.41
0.03%
Ethereum(ETH)
€2,263.05
1.72%
Fesseln(USDT)
€0.88
0.00%
XRP(XRP)
€1.92
0.72%
Solana(SOL)
€137.03
-0.52%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.170792
0.55%
Shiba Inu(SHIB)
€0.000011
1.48%
Pepe(PEPE)
€0.000011
3.55%
Peanut das Eichhörnchen(PNUT)
€0.238484
2.18%
Nach oben scrollen