Database/Kernel, userspace & hypervisor
Linux kernel (OverlayFS/FUSE): OverlayFS copies setuid files from a nosuid FUSE mount
Impact
OverlayFS copies setuid files from a nosuid FUSE mount - unprivileged local user to root, a live container-escape chain [KEV]
Who can reach it
Any tenant process in a container with a user namespace
What to do
Livepatchable; otherwise drain + reboot. Compensating control: disallow unprivileged FUSE mounts
Fleet impact
How widespread
Universal - kernels 5.11-6.1.8, and OverlayFS *is* the container storage driver on every containerized GPU host
Cost to remediate
node-reboot - kernel upgrade; no meaningful runtime mitigation since disabling OverlayFS breaks container storage
Why it hits the whole fleet
Copying a setuid binary across a nosuid OverlayFS mount preserves capabilities, giving any regular user root; inside a container it gives container-root, which then chains into the cgroup/procfs escapes above on a shared GPU host
References
Related entries
- Linux kernel (arch/s390/pci): When an SR-IOV VF is hot-unplugged its MMIO resources are freed, but the parent bus keepsCVE-2023-53123 · Linux kernel (arch/s390/pci)High
- Linux kernel (perf): Out-of-bounds write in perf_read_group() via read_size overflow - local rootCVE-2023-6931 · Linux kernel (perf)High
- Linux kernel (IGMP): Use-after-free in IPv4 IGMP - local privilege escalationCVE-2023-6932 · Linux kernel (IGMP)High
- Linux kernel (kTLS): splice() into a kTLS socket overwrites read-only kernel pages - local privilege escalationCVE-2024-0646 · Linux kernel (kTLS)High
- OpenSSH (sshd, RHEL9): Signal-handling race in the privsep child - possible RCE, RHEL 9 specificCVE-2024-6409 · OpenSSH (sshd, RHEL9)High
- sudo: Local privilege escalation via the `--host` option against host-specific sudoers rulesCVE-2025-32462 · sudoHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.