PT-2021-4253 · Linux+3 · Linux Kernel+3

Published

2021-04-12

·

Updated

2026-04-04

·

CVE-2021-3493

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel versions prior to the fixed version
Description The overlayfs implementation in the Linux kernel did not properly validate the setting of file capabilities on files in an underlying file system with respect to user namespaces. This issue, combined with a patch in the Ubuntu kernel to allow unprivileged overlay mounts, allows an attacker to gain elevated privileges.
Recommendations For Linux Kernel versions prior to the fixed version, consider disabling the overlayfs feature until a patch is available. Restrict access to unprivileged user namespaces and overlay mounts to minimize the risk of exploitation. Avoid using the overlayfs module in sensitive environments until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2021-04861
CVE-2021-3493
LSN-0076-1
USN-4915-1
USN-4916-1
USN-4916-2
USN-4917-1

Affected Products

Astra Linux
Linux Kernel
Linuxmint
Ubuntu