Ubuntu USN · July 2026

Ubuntu Linux Security Advisory: July 2026 OverlayFS & Memory Triage

Triage of Ubuntu's July 2026 kernel updates fixing critical OverlayFS file capability bypasses and container security isolation bugs.

41
CVEs Remediated
1
Container Escape
7.8
CVSS OverlayFS
High
Kubernetes Host Urgency

보안 릴리스 분석 및 위험성 평가

Ubuntu's July 2026 security update addresses CVE-2023-2640 (GameOver(lay)), where Ubuntu-specific modifications to OverlayFS skipped permission checks during inode copy-up, enabling unprivileged container processes to create root setuid binaries on the host filesystem.

핵심 취약점 트리아지 매트릭스

CVE 식별자 서브시스템 / 구성 요소 영향 CVSS 실제 악용 여부?
CVE-2023-2640OverlayFS Inode Copy-UpPermission Bypass / LPE7.8 HighYES (In-The-Wild)
CVE-2024-35860SMB / CIFS ClientNull Pointer Dereference5.3 MediumNo
CVE-2024-35861NVMe DriverRace Condition / Memory Leak6.1 MediumNo
주목할 코드 분석

Deep Dive: Ubuntu OverlayFS Inode Copy-Up Privilege Escalation Teardown →

Review the exact C source patch showing how Ubuntu's custom ovl_do_setxattr bypassed security checks when handling privileged capabilities.

← 전체 보안 디렉터리 보기 모든 플랫폼 보안 업데이트 →