Ubuntu USN · July 2026

Ubuntu Linux Security Advisory: July 2026 OverlayFS & Memory Triage

Triage of Ubuntu's July 2026 kernel updates fixing critical OverlayFS file capability bypasses and container security isolation bugs.

41
CVEs Remediated
1
Container Escape
7.8
CVSS OverlayFS
High
Kubernetes Host Urgency

セキュリティトリアージとリスク評価

Ubuntu's July 2026 security update addresses CVE-2023-2640 (GameOver(lay)), where Ubuntu-specific modifications to OverlayFS skipped permission checks during inode copy-up, enabling unprivileged container processes to create root setuid binaries on the host filesystem.

優先脆弱性トリアージマトリックス

CVE識別番号 対象サブシステム / コンポーネント 影響範囲 CVSS ゼロデイ悪用確認?
CVE-2023-2640OverlayFS Inode Copy-UpPermission Bypass / LPE7.8 HighYES (In-The-Wild)
CVE-2024-35860SMB / CIFS ClientNull Pointer Dereference5.3 MediumNo
CVE-2024-35861NVMe DriverRace Condition / Memory Leak6.1 MediumNo
注目ソースコード分析

Deep Dive: Ubuntu OverlayFS Inode Copy-Up Privilege Escalation Teardown →

Review the exact C source patch showing how Ubuntu's custom ovl_do_setxattr bypassed security checks when handling privileged capabilities.

← セキュリティディレクトリ一覧 すべてのセキュリティ更新情報 →