Nearly half of Ubuntu users could be vulnerable to these security flaws
Wiz researchers Sagi Tzadik and Shir Tamari have identified a pair of vulnerabilities that are estimated to be affecting two in five Ubuntu users, so users of the popular Linux distro are being urged to update now.
The vulnerabilities, being tracked as CVE-2023-32629 and CVE-2023-2640, were both dealt with in the latest patch available for Ubuntu 23.04 Lunar Lobster.
Still, many users won’t have applied the necessary update yet which is problematic because Tzadik and Tamari say that exploits for these vulnerabilities are already publicly available.
Update your Ubuntu now
Both problems stem, say the researchers, from when the Linux kernel project made modifications to the OverlayFS module in 2019 and 2022, which conflicted with Ubuntu’s earlier changes. When the new code was adopted by Ubuntu, both CVEs became apparent.
The Wiz advisory reads: “OverlayFS serves as an attractive attack surface for local privilege escalation since it is often accessible to unprivileged users via user namespaces, it has a history of numerous logical vulnerabilities that were easy to exploit, and it has a relatively active code base.”
For both CVE-2023-32629 and CVE-2023-2640, Ubuntu said: “the OverlayFS implementation in the Ubuntu Linux kernel did not properly perform permission checks in certain situations.” This led to the potential for a local attacker to gain elevated privileges.
At the same time, Linux applied fixes for six other vulnerabilities. Ubuntu says that a reboot is required after an update to ensure that the changes have taken effect.
Given the far reach of these vulnerabilities because of the popularity of OverlayFS, and their severity (one marked as high, the other as medium), users should look to apply updates even if they are unsure of their particular setups or that they think they have already updated recently.
Wiz researchers Sagi Tzadik and Shir Tamari have identified a pair of vulnerabilities that are estimated to be affecting two in five Ubuntu users, so users of the popular Linux distro are being urged to update now. The vulnerabilities, being tracked as CVE-2023-32629 and CVE-2023-2640, were both dealt with in…
Recent Posts
- How to watch the World Cup Final ‘66 In Colour for *FREE*
- ‘Elon Musk said he thinks humanoid robots will be in many homes in three years, and I agree with him.’ I sat down with Jake Dyson to hear his predictions for AI and robotics in your home — and why you shouldn’t throw out your stick vac just yet
- LaCie 8big Pro5 review: I tested LaCie’s huge 256TB DAS solution, and it’s ideal for 8K video editing but it comes with a price tag that’s just as big
- EA’s Star Wars Zero Company drops August 27
- Amazon Prime members can already get $135 in free perks ahead of Prime Day 2026 — here are 7 freebies to claim right now
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023