Triage of Ubuntu's July 2026 kernel updates fixing critical OverlayFS file capability bypasses and container security isolation bugs.
| Идентификатор CVE | Подсистема / Компонент | Последствия | CVSS | Активная эксплуатация? |
|---|---|---|---|---|
| CVE-2023-2640 | OverlayFS Inode Copy-Up | Permission Bypass / LPE | 7.8 High | YES (In-The-Wild) |
| CVE-2024-35860 | SMB / CIFS Client | Null Pointer Dereference | 5.3 Medium | No |
| CVE-2024-35861 | NVMe Driver | Race Condition / Memory Leak | 6.1 Medium | No |
Review the exact C source patch showing how Ubuntu's custom ovl_do_setxattr bypassed security checks when handling privileged capabilities.