CVE-2021-3493

unknown KEV
Published 2022-10-20 · Modified 2022-10-20
CVSS v3
CVSS v2
VIR risk
1.5

Description

The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.

CISA KEV

Vendor
Linux
Product
Kernel
Due date
2022-11-10

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7c03e2cda4a584cadc398e8f6641ca9988a39d52; https://nvd.nist.gov/vuln/detail/CVE-2021-3493

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-3493

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-3493.html

Exploits

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed5.10.38-1
debian debianbullseyefixed5.10.38-1
debian debianforkyfixed5.10.38-1
debian debiansidfixed5.10.38-1
debian debiantrixiefixed5.10.38-1

References

Verify integrity in audit chain (admin only). AS-IS.