CVE-2021-3493
Summary
| CVE | CVE-2021-3493 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-17 05:15:00 UTC |
| Updated | 2023-07-07 19:10:00 UTC |
| Description | The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges. |
Risk And Classification
EPSS: 0.771920000 probability, percentile 0.989620000 (date 2026-04-01)
CISA KEV: Listed on 2022-10-20; due 2022-11-10; ransomware use Unknown
Problem Types: CWE-863
CISA Known Exploited Vulnerability
| Vendor | Linux |
|---|---|
| Product | Kernel |
| Name | Linux Kernel Privilege Escalation Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7c03e2cda4a584cadc398e8f6641ca9988a39d52; https://nvd.nist.gov/vuln/detail/CVE-2021-3493 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | All | All | All | All |
| Operating System | Canonical | Ubuntu Linux | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Ubuntu Overlayfs Local Privilege Escalation ≈ Packet Storm | MISC | packetstormsecurity.com | |
| oss-security - [CVE-2021-3493] Ubuntu Linux kernel overlayfs fs caps privilege escalation | MISC | www.openwall.com | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MISC | git.kernel.org | |
| Ubuntu OverlayFS Local Privilege Escalation ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Kernel Live Patch Security Notice LSN-0076-1 ≈ Packet Storm | MISC | packetstormsecurity.com | |
| USN-4917-1: Linux kernel vulnerabilities | Ubuntu security notices | Ubuntu | MISC | ubuntu.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Vendor Comments And Credit
Discovery Credit
LEGACY: An independent security researcher reporting to the SSD Secure Disclosure program
Legacy QID Mappings
- 180539 Debian Security Update for linux (CVE-2021-3493)
- 198331 Ubuntu Security Notification for Linux kernel (OEM) vulnerabilities (USN-4915-1)
- 198332 Ubuntu Security Notification for Linux kernel vulnerabilities (USN-4916-1)
- 198333 Ubuntu Security Notification for Linux kernel vulnerabilities (USN-4917-1)