CVE-2021-3493
Linux Kernel Privilege Escalation Vulnerability
- Published
- Apr 17, 2021
- Updated
- Oct 21, 2025
- Assigning CNA
- canonical
- Evidence observed
- Oct 20, 2022
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 98.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.
Sources
18Two-stage proof-of-concept for CVE-2021-3493, exploiting Ubuntu OverlayFS to escalate from unprivileged user to root via file capability manipulation in user namespaces.
- CVE-2021-3493Exploit
Local privilege escalation exploit for Ubuntu OverlayFS flaw CVE-2021-3493; compiles with gcc and runs to gain elevated privileges on affected Ubuntu versions.
- CVE-2021-3493Exploit
Ubuntu OverlayFS Local Privesc
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.