← Back

CVE-2021-3493

nvd nist
Published: Apr 17, 2021Modified: Oct 28, 2025CISA KEV

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.

Affected (3)

1 product
Ubuntu Linux
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Before 18.04
From 18.04.1 to 20.04
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 20.10

References (13)

Source: security@ubuntu.com
ExploitThird Party AdvisoryVDB Entry
Source: security@ubuntu.com
Press/Media CoverageThird Party AdvisoryVDB Entry
Source: security@ubuntu.com
ExploitThird Party AdvisoryVDB Entry
Source: security@ubuntu.com
Vendor Advisory
Source: security@ubuntu.com
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Press/Media CoverageThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.