CVE-2021-3493
Linux Kernel: Privilege Escalation
As of , CVE-2021-3493 in Linux Kernel is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 20 October 2022
- US federal deadline
- 10 November 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.49Higher than 98% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- 0.09 on 20 October 2022EPSS on the day CISA listed it.
- Public exploit
- 1 Metasploit module
- Fix
- Vendor advice: git.kernel.orgLinks below, from CISA's entry.
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.
CISA's description
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.
The CVE record's description, from canonical
- CVE published
- 17 April 2021
- Assigned by
- canonical
- CVSS
- 8.8 High (CVSS 3.1, from the CNA)
- CWE-270
- Privilege Context Switching Error
- CWE-862
- Missing Authorization
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: 2021 Ubuntu Overlayfs LPEexploit module, rank great
Kernel: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-39682Improper Check for Unusual or Exceptional Conditions | Linux Kernel | Patch nowForensic triage required by CISA | 0.03 | ||
| CVE-2025-39964Race Condition | Linux Kernel | Patch nowForensic triage required by CISA | 0.01 | ||
| CVE-2026-53266Out-of-Bounds Write | Linux Kernel | Patch nowForensic triage required by CISA | 0.01 | ||
| CVE-2026-53362Unspecified | Linux Kernel | Patch nowForensic triage required by CISA | 0.01 | ||
| CVE-2021-22555Heap Out-of-Bounds Write | Linux Kernel | Patch this weekMetasploit module; EPSS 0.79; verified Exploit-DB entry | 0.79 | ||
| CVE-2013-6282Improper Input Validation | Linux Kernel | Patch this weekMetasploit module; verified Exploit-DB entry | 0.40 | ||
| CVE-2019-13272Improper Privilege Management | Linux Kernel | Patch this weekMetasploit module; EPSS 0.52; verified Exploit-DB entry | 0.52 | ||
| CVE-2010-3904Improper Input Validation | Linux Kernel | Patch this weekMetasploit module; verified Exploit-DB entry | 0.16 | ||
| CVE-2022-0847Privilege Escalation | Linux Kernel | Patch this weekMetasploit module; EPSS 0.93 | 0.93 | ||
| CVE-2014-3153Privilege Escalation | Linux Kernel | Patch this weekMetasploit module | 0.37 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org