peter bassill · operator
$ cve CVE-2021-3493 JSON

CVE-2021-3493 KEV

8.8
HIGH · CVSS 3.1 · EPSS 49.2% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-11-10.

Description

The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS49.17% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-270
On CISA KEVyes — remediate by 2022-11-10
Public exploitnone known
Published2021-04-17
Last modified2026-06-17

CISA KEV

NameLinux Kernel Privilege Escalation Vulnerability
Added2022-10-20
Due2022-11-10
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (1)

VendorProduct
canonicalubuntu linux

References

→ the Explorer  ·  watch your stack  ·  NVD