CVE-2021-3493
HIGH KEV2021 Ubuntu Overlayfs LPE
Title source: metasploitDescription
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.
Exploits (24)
nomisec
WORKING POC
by iqbalhussainas · local
https://github.com/iqbalhussainas/OverlayFS-LPE-Exploit
nomisec
WORKING POC
by Psychopath-Traveler · local
https://github.com/Psychopath-Traveler/CVE-2021-3493
metasploit
WORKING POC
by g1vi, h00die, bwatters-r7, gardnerapp · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/gameoverlay_privesc.rb
metasploit
WORKING POC
GREAT
by ssd-disclosure, bwatters-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/cve_2021_3493_overlayfs.rb
References (7)
Scores
CVSS v3
8.8
EPSS
0.7524
EPSS Percentile
98.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Details
CISA KEV
2022-10-20
VulnCheck KEV
2022-10-20
InTheWild.io
2022-09-06
ENISA EUVD
EUVD-2021-26815
CWE
CWE-270
CWE-863
Status
published
Products (2)
canonical/ubuntu_linux
< 18.04
canonical/ubuntu_linux
< 20.10
Published
Apr 17, 2021
KEV Added
Oct 20, 2022
Tracked Since
Feb 18, 2026