PT-2022-6438 · Linux+2 · Linux Kernel+2

Alon Zahavi

·

Published

2022-04-01

·

Updated

2026-03-14

·

CVE-2021-3847

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to an unauthorized access flaw in the Linux kernel OverlayFS subsystem. This flaw can be exploited by a local user to escalate their privileges on the system. The problem arises when a user copies a capable file from a nosuid mount into another mount.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1647
ALT-PU-2022-1730
ALT-PU-2022-1768
ALT-PU-2022-2155
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-9301
BDU:2023-01298
CVE-2021-3847
ECHO-E420-F8E4-BE6F

Affected Products

Alt Linux
Debian
Linux Kernel