CVE-2023-32629PoC(canonical / ubuntu_linux)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for canonical ubuntu_linux systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernels

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ubuntu_linux

Threat summary

  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ubuntu_linux

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-11: 1PoC Mentioned / Linked · 2026-05-11: 1Exploit Tool / Code · 2026-05-11: 1Technical Details · 2026-05-11: 105-11
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • c0deNinja@gotr00t0day
    PoC

    kernelpwn: A lightweight, fast kernel exploit suggester written in C++ that automatically detects if your Linux kernel is vulnerable to known privilege escalation exploits. These are the vulnerabilities that kernelpwn can detect: 1. Dirty COW (CVE-2016-5195) 2. Dirty Pipe (CVE-2022-0847) 3. GameOver(lay) (CVE-2023-32629) 4. CVE-2024-1086 5. Copy Fail 6. Dirty Frag Github: https://github.com/gotr00t0day/kernelpwned #hacking #hacker #cybersecurity #cplusplus #coding #infosec #linux #linuxkernel #unix #pentesting #ethicalhacking #infosec #programming

    Post summary

    The post presents a C++ tool that detects multiple kernel CVEs and links to its code repository, but it does not report active exploitation, patches, or debunking.

    00020152
    555 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OScanonicalubuntu_linux23.04--

Explore more