VDB

CVE-2021-3493

CVE-2021-3493 PUBLISHED KEV

The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.

EPSS 79.71% · 99.1th percentile

Risk Scores

EPSS Score
79.71%
99.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-gcp-5.45.4.0-1024.24~18.04.1, 5.4.0-1028.29~18.04.1, 5.4.0-1025.25~18.04.1
Ubuntu:16.04:LTSlinux-raspi24.4.0-1141.151, 4.4.0-1136.145, 4.4.0-1137.146
Ubuntu:20.04:LTSlinux-riscv-5.8*, *, 5.8.0-20.22~20.04.1
Ubuntu:20.04:LTSlinux-azure5.3.0-1003.3, 0, 5.4.0-1040.42
Ubuntu:20.04:LTSlinux-gcp5.4.0-1032.34, 5.4.0-1036.39, 5.4.0-1037.40
Ubuntu:20.04:LTSlinux-raspi25.3.0-1007.8, 5.3.0-1014.16, 0
Ubuntu:16.04:LTSlinux-aws-hwe4.15.0-1045.47~16.04.1, 4.15.0-1044.46~16.04.1, 4.15.0-1043.45~16.04.1
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-aws-fips0, *
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-azure-fips5.4.0-1022.22+fips1, 0
Ubuntu:16.04:LTSlinux-azure4.15.0-1057.62, *, 4.15.0-1055.60
Ubuntu:18.04:LTSlinux-hwe5.0.0-23.24~18.04.1, 5.0.0-25.26~18.04.1, *
Ubuntu:18.04:LTSlinux-raspi24.15.0-1034.36, 4.15.0-1032.34, 4.15.0-1054.58
Ubuntu:18.04:LTSlinux-aws-5.05.0.0-1025.28, 0, *
Ubuntu:18.04:LTSlinux-aws4.15.0-1058.60, 0, 4.15.0-1001.1
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-azure-fips4.15.0-2006.7, 4.15.0-2024.27, 0
Ubuntu:Pro:FIPS:18.04:LTSlinux-aws-fips0, 4.15.0-2000.4
Ubuntu:18.04:LTSlinux-gke-5.30, 5.3.0-1011.12~18.04.1, 5.3.0-1012.13~18.04.1
Ubuntu:18.04:LTSlinux-snapdragon4.15.0-1069.76, 4.15.0-1067.74, 4.15.0-1066.73
Ubuntu:18.04:LTSlinux-azure-5.45.4.0-1031.32~18.04.1, 0, *
Ubuntu:18.04:LTSlinux-gke-5.45.4.0-1035.37~18.04.1, 5.4.0-1039.41~18.04.1, *

…and 59 more

Timeline

  • Jan 16, 1970 VulnCheck XDB Entry
  • Jan 16, 1970 VulnCheck XDB Entry
  • Jan 17, 1970 VulnCheck XDB Entry
  • Jan 19, 1970 VulnCheck XDB Entry
  • Jan 19, 1970 VulnCheck XDB Entry
  • Jan 19, 1970 VulnCheck XDB Entry
  • Jan 19, 1970 VulnCheck XDB Entry
  • Jan 19, 1970 VulnCheck XDB Entry
  • Jan 19, 1970 VulnCheck XDB Entry
  • Jan 19, 1970 VulnCheck XDB Entry
  • Jan 19, 1970 VulnCheck XDB Entry
  • Jan 19, 1970 VulnCheck XDB Entry
Open in Interactive Console →
$ Console Community · 100/wk Open console ›