Vulnerability record · CVE-2021-3493 · published 17 April 2021
CVE-2021-3493: Ubuntu Linux kernel overlayfs file capability privilege escalation
Canonical · Ubuntu Linux
The Linux kernel overlayfs implementation failed to properly validate file capability settings on files in an underlying filesystem with respect to user namespaces. Combined with an Ubuntu-specific patch allowing unprivileged overlay mounts, this lets a local user escalate privileges. It matters because the flaw is in the kernel, affects Ubuntu systems, and is listed in CISA KEV.
Description
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityLocal privilege escalation to root on Ubuntu with public exploits and KEV listing, though it requires an existing local account.
What it is
The Linux kernel overlayfs implementation failed to properly validate file capability settings on files in an underlying filesystem with respect to user namespaces. Combined with an Ubuntu-specific patch allowing unprivileged overlay mounts, this lets a local user escalate privileges. It matters because the flaw is in the kernel, affects Ubuntu systems, and is listed in CISA KEV.
Impact
An attacker with a local account gains elevated privileges, up to root, on the affected host. That yields full control of the system, including data, other users' processes, and kernel-level operations.
Attack surface
Reached locally by an authenticated user who can create unprivileged user namespaces and overlay mounts; no user interaction beyond running the exploit is needed. The CVSS vector is AV:L/PR:L/UI:N, confirming local access with low privileges.
Exploitation
CVE-2021-3493 is in CISA KEV (added 2022-10-20) and has an EPSS 30-day probability of about 0.49 (98.8th percentile). Multiple references are tagged Exploit, indicating public exploit code exists.
What to do
- Apply the Ubuntu kernel update per USN-4917-1 and reboot or use kernel livepatch where applicable.
- Restrict unprivileged user namespaces (e.g., kernel.unprivileged_userns_clone=0) where the workload permits.
- Limit local shell access and audit accounts that can create user namespaces or overlay mounts.
- Track KEV remediation due date (2022-11-10) and confirm all affected Ubuntu kernels are patched.
Detection
- Monitor for unexpected creation of user namespaces and overlay mounts by non-privileged users.
- Alert on processes gaining root or changing file capabilities outside normal change windows.
- Hunt for known public exploit artifacts or command patterns associated with overlayfs capability abuse.
- Review kernel and audit logs for privilege escalation attempts from low-privileged accounts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-3493 to the Known Exploited Vulnerabilities catalog on 20 October 2022 as "Linux Kernel Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 November 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-3493 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-3493), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.