Nearly half of Ubuntu users could be vulnerable to these security flaws

Ubuntu
(Image credit: Future)

Wiz researchers Sagi Tzadik and Shir Tamari have identified a pair of vulnerabilities that are estimated to be affecting two in five Ubuntu users, so users of the popular Linux distro are being urged to update now.

The vulnerabilities, being tracked as CVE-2023-32629 and CVE-2023-2640, were both dealt with in the latest patch available for Ubuntu 23.04 Lunar Lobster.

Still, many users won’t have applied the necessary update yet which is problematic because Tzadik and Tamari say that exploits for these vulnerabilities are already publicly available.

Update your Ubuntu now

Both problems stem, say the researchers, from when the Linux kernel project made modifications to the OverlayFS module in 2019 and 2022, which conflicted with Ubuntu’s earlier changes.  When the new code was adopted by Ubuntu, both CVEs became apparent.

The Wiz advisory reads: “OverlayFS serves as an attractive attack surface for local privilege escalation since it is often accessible to unprivileged users via user namespaces, it has a history of numerous logical vulnerabilities that were easy to exploit, and it has a relatively active code base.”

For both CVE-2023-32629 and CVE-2023-2640, Ubuntu said: “the OverlayFS implementation in the Ubuntu Linux kernel did not properly perform permission checks in certain situations.” This led to the potential for a local attacker to gain elevated privileges.

At the same time, Linux applied fixes for six other vulnerabilities. Ubuntu says that a reboot is required after an update to ensure that the changes have taken effect.

Given the far reach of these vulnerabilities because of the popularity of OverlayFS, and their severity (one marked as high, the other as medium), users should look to apply updates even if they are unsure of their particular setups or that they think they have already updated recently.

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Security
Broadcom releases fixes for multiple VMware security flaws
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
Representational image depecting cybersecurity protection
OpenSSH vulnerabilities could pose huge threat to businesses everywhere
Representational image depecting cybersecurity protection
Ivanti reveals major security update, so make sure you're protected
Digital image of a lock.
Nvidia systems could be facing another worrying security flaw
Representational image of a cybercriminal
Microsoft just patched a host of worrying security issues, so update now
Latest in Pro
Branch office chairs next to a TechRadar-branded badge that reads Big Savings.
This office chair deal wins the Amazon Spring Sale for me and it's so good I don't expect it to last
Saily eSIM by Nord Security
"Much more than just an eSIM service" - I spoke to the CEO of Saily about the future of travel and its impact on secure eSIM technology
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
FlexiSpot office furniture next to a TechRadar-branded badge that reads Big Savings.
Upgrade your home office for under $500 in the Amazon Spring Sale: My top picks and biggest savings
Beelink EQi 12 mini PC
I’ve never seen a PC with an Intel Core i3 CPU, 24GB RAM, 500GB SSD and two Gb LAN ports sell for so cheap
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring