CVE-2021-3493
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Linux Kernel Privilege Escalation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 44% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-270, CWE-863
מוצרים מושפעים
canonical: ubuntu linux
קישורים
- https://ubuntu.com/security/notices/USN-4917-1 Vendor Advisory
- https://ubuntu.com/security/notices/USN-4917-1 Vendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=… Mailing ListPatchThird Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=… Mailing ListPatchThird Party Advisory
- http://packetstormsecurity.com/files/162434/Kernel-Live-Patch-Security-Notice-… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/165151/Ubuntu-Overlayfs-Local-Privilege-E… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162434/Kernel-Live-Patch-Security-Notice-… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/165151/Ubuntu-Overlayfs-Local-Privilege-E… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162866/Ubuntu-OverlayFS-Local-Privilege-E… Press/Media CoverageThird Party AdvisoryVDB Entry
- https://www.openwall.com/lists/oss-security/2021/04/16/1 Mailing ListThird Party Advisory